Live data from Hacker News

Ask HN: Could EU residents comment on how the GDPR has improved their privacy?

news.ycombinator.com

61–70 of 78 posts

Re: Ask HN: Could EU residents comment on how the GDPR has improved their privacy?

#61

This has improved privacy awareness, curbed data hoarding and reduces tracking across the board. It also made people aware of which companies don't have their IT in correct order. (i.e. those that outright ban EU traffic, or don't prompt to ask if they can hoard your data)

> [those that] don't prompt to ask if they can hoard your data [don't have their IT in correct order]

It's kind of the opposite: if they need to ask for your consent, that means they're doing something that is not part of the standard exceptions.

For example, if they only use your data to do what you asked them to do, they don't need consent. If I ask Contoso to ship me a horse, they don't need my consent to process my address.

Every time you see a cookie banner, the message is: we want to invade your privacy.

If you want to find those that don't have their data protection in order, look for sites without privacy policy, or policies that were updated prior to ~2016 (that's when the GDPR text was finalized, i.e. the earliest time they could have updated it to be compliant with new requirements). A cookie wall is a signal that it's bad, not that it's good.

Re: Ask HN: Could EU residents comment on how the GDPR has improved their privacy?

#62
post #19

Popups everywhere. Insane bureaucracy, even at the doctor. And when it matters, it's just being ignored. Most (medium-sized) companies haven't even realized there is a new law.

Popup situation is really bad There should be a standard implementation of these popups so that I don't have to do it for each new website on each new browser again and again.

That would not be legally valid: you can't give a blanket consent for an unspecified party to do anything with your personal data.

Also, as I mentioned in another comment just now (https://news.ycombinator.com/item?id=21857843), the banner means they want to do something that you probably don't want, because that's why they have to ask consent. The banner is not needed for things like visitor counting, browsing products in a webshop, or other expected operations that involve personal data. It's only necessary when they do something that requires consent (see the link for an example).

Re: Ask HN: Could EU residents comment on how the GDPR has improved their privacy?

#63

Yes - from inside knowledge, the lead/customer data being sold from business to business has either massively changed or completely stopped. Personally, I barely receive any out of the blue marketing calls or texts anymore. If someone dubious market’s me via phone or email, I know my rights and I can follow how they acquired my data and who sold them my personal details. As a software developer/entrepreneur, it made…

> I barely receive any out of the blue marketing calls or texts anymore

That's strange, as anti-spam legislation is completely separate from GDPR and has been in place for much longer. The only connection I see is that data brokers got a harder time selling your data to these third parties that would call or text you, but what those third parties were doing was already illegal and still is for the same reason (so not because of GDPR).

In the Netherlands it hasn't been legal to cold call someone that opted out of cold calls (using a national register of phone numbers that don't want to be called) since 2009. Any marketing call you do receive has to offer enrolling you on this list to prevent future calls.

For email, again speaking of Dutch laws, companies are not allowed to send you unsolicited, promotional messages. Not sure as of which year this is, but it has been the case for as long as I remember.

I assume most EU countries have similar constructions (I'm not sure if our laws are based on a EU directive).

Re: Ask HN: Could EU residents comment on how the GDPR has improved their privacy?

#64
post #14

Well, the cookie popups have helped me become more selective in my browsing. If they don't make it reasonably easy to opt out, I just don't open the site. But the real benefit is this: Some random online store that i bought something from once decided to send me a spam sms around black friday. One email and 24 hours later, all the data they had about me was deleted. Of course, this only works if you're in europe buyi…

A few notes:

> One email and 24 hours later, all the data they had about me was deleted.

You make it sound as if this is new, but this was also possible under the DPD from the late 90s. GDPR didn't improve that. (What helped is that GDPR isn't from the late 90s but was introduced in a year where privacy was already a hot topic, so it was picked up by the media and now companies actually know about it so you don't have to point out the law before they understand what you're talking about when you do an access/deletion request. But it technically hasn't changed.)

> this only works if you're in europe buying from an european store

Sort of. While the EU claims it applies to anyone, the Chinese government isn't going to give a rat's ass if you sue and win a court case against a Chinese company. However, if that Chinese company has assets in the EU, they can be seized, not to mention that they can probably be banned from the EU market altogether.

Anyone who wishes to continue selling to Europeans and not have any European assets seized would do well to comply with European law, also if their headquarters / choice of court / assets is/are outside the EU.

Re: Ask HN: Could EU residents comment on how the GDPR has improved their privacy?

#65
post #54

Earlier quoted context omitted.

Any opt-out popups anyway aren't caused by GDPR anyway, as consent is 'GDPR-kosher' only if it's explicitly opt-in. If I take no action, accept the default conditions and don't opt out of anything, then that must be interpreted as me not granting permission to anything - there are a bunch of data use-cases that you're allowed to do without my consent, so you don't need the popups for that, but otherwise no informed e…

That's how it should work, but in practice most popups are opt out. I've seen only one type of cookie popup that comes with default opt in, and even that one has a very proeminent 'opt in to all and save' button and a slightly harder to find 'just save' button that will actually allow the opt out to stay.

I find it interesting how Google still does this on sites like blogger. I ignore the banner covering 80% of my mobile screen and read the article but agree to nothing. They'll probably still process my data despite me not agreeing to it, and when the day comes, someone will sue them, an investigation will be held, and a large fine will be collected.

What I find strange is that google's army of lawyers doesn't seem worried about this.

Re: Ask HN: Could EU residents comment on how the GDPR has improved their privacy?

#66
Had an old debt I never honoured, but still under law it became invalid and extinct. Yet it gets resold and some specialist companies try to get anything from you, under 'amicable' terms.

They were harassing me, calling etc, and I wondered how they got my details after so long. Made requests for data they held on me, and complained to CNIL about their practices. They dropped everything and are now being investigated by CNIL on how they handle GDPR.

Re: Ask HN: Could EU residents comment on how the GDPR has improved their privacy?

#67
post #29

I operate a B2B SaaS. We sell a service to other SaaS companies. To deliver our service, we are sent PII from our customers which we process as a subprocessor under GDPR. From the perspective of selling a B2B SaaS service, GDPR has been incredibly successful at making Security & Compliance an important discussion that is had during the sales process. Most leads will have security/compliance as an agenda item during s…

We're not a SaaS - but we noticed GDPR appearing as a requirement in RFx's

Our software does contain customer information, but isn't the focus. As somebody actually designed it properly, compliance wasn't particularly arduous. Huge sections simply didn't apply, and where it did we could just link each requirements to the relevant details, API, logs etc.

As you mention, I think the main benefit is just formalizing something that should already have been designed.

Another benefit is that it's driven 'bottom up' - Customer doesn't have to pay every vendor to provide them a new feature for say "scrubbing a customer". All their providers supply "here's how you scrub in my product" and customer just needs to stitch these mechanisms together to give their customers the ability to be scrubbed.

Re: Ask HN: Could EU residents comment on how the GDPR has improved their privacy?

#69
Having used the ICO to try and stop a company illegally collecting biometric information for access to a gym I am not confident it is very effective. Not only did the gym not stop but the ICO all but rubber-stamped what they were doing. Just like the data protection act before it on a daily basis on the web you see companies openly breaking the law with the wrong defaults and reports just disappear into a pit with the ICO.

The law exists but it isn't enforced by the regulator and the way the GDPR law is set up there is no way to bring private prosecutions to enforce fines and get the law applied. So since the regulator isn't doing it the law is effectively useless. Some companies are complying but the bad ones are seeing no consequences and the compliant ones are bound to notice soon that they can safely ignore it completely soon enough. It has no enforcement currently, there is no rush to ensure your company complies.

Re: Ask HN: Could EU residents comment on how the GDPR has improved their privacy?

#70
Most remain invisible to customers and externals. However, inside just one company, there are dozens of smaller projects that's fixed security and privacy issues across all the horizontals: front end, ESB, middleware, databases, applications, you name it.

Without GDPR the majority of those hidden improvements would've been postponed indefinately.

I do regard spammy notifications as regressions though.

Post reply on HN