Live data from Hacker News

Show HN: Databunker – a GDPR compliant, secure storage for personal data (PII)

github.com

11–20 of 35 posts

Re: Show HN: Databunker – a GDPR compliant, secure storage for personal data (PII)

#13

> and you still need to consult with an attorney specializing in privacy. Governments should be refunding solicitor costs to anyone needing GDPR advice. Otherwise this is just another way to add barriers. If you are on modest income you can forget about setting up a website in the EU.

> Otherwise this is just another way to add barriers.

Personally I think pretty much everything in GDPR is just sensible guidelines for how to handle personal data, and if you're not willing to do those things then you probably shouldn't be handling personal data in the first place. Being ignorant of good data practice is not an excuse.

> If you are on modest income you can forget about setting up a website in the EU.

This is just rubbish. GDPR only applies to personal info for a start so if you don't store personal info then you have nothing to worry about. Even if you do store personal info the vast majority of use cases are really straightforward and require a very minimal understanding of the law to be compliant.

Re: Show HN: Databunker – a GDPR compliant, secure storage for personal data (PII)

#16
post #4

> and you still need to consult with an attorney specializing in privacy. Governments should be refunding solicitor costs to anyone needing GDPR advice. Otherwise this is just another way to add barriers. If you are on modest income you can forget about setting up a website in the EU.

The law is quite readable, and the various Data Protection Agencies (country-specific regulators) have provided more concrete guidance. If you're setting up a website that takes a restrained approach to personal data, you don't necessarily need an attorney.

Databunker turns basically any startup to be privacy by design compliant.

Re: Show HN: Databunker – a GDPR compliant, secure storage for personal data (PII)

#17
post #13

> and you still need to consult with an attorney specializing in privacy. Governments should be refunding solicitor costs to anyone needing GDPR advice. Otherwise this is just another way to add barriers. If you are on modest income you can forget about setting up a website in the EU.

> Otherwise this is just another way to add barriers. Personally I think pretty much everything in GDPR is just sensible guidelines for how to handle personal data, and if you're not willing to do those things then you probably shouldn't be handling personal data in the first place. Being ignorant of good data practice is not an excuse. > If you are on modest income you can forget about setting up a website in the EU…

Furthermore you can often ask them for help (or so I have heard).

Re: Show HN: Databunker – a GDPR compliant, secure storage for personal data (PII)

#18

Nice project, although I have question I would appreciate someone can answer. How does in real world "right to forget" works. What is confusing part for me that data that identify you are also required for the business, so how do you draw line what can be forgotten and what cannot. Let say I use some service, then I violate policies of that company, then I exercise my "right to forget", and after they delete my data…

I am no expert on GDPR or security, but wouldn't a simple "PII to Cryptologically Secure Hash" solution work for some of this? The PII would possibly need to be accessed piecemeal while the account is active, so hashing is not appropriate alone, but once the account is deleted you could store a user's hash (or partial hash, made from only truly unique info or info combos) since it cannot be reconstituted and contains no specific PII. You then store this hash in your "abusive person" list, or whatever, maybe link it to refund data if needed, and if a "forgotten" user needs to interact with the service they fill in their information which is converted to the hash without saving. Doable?

Re: Show HN: Databunker – a GDPR compliant, secure storage for personal data (PII)

#19
post #10
post #6

Earlier quoted context omitted.

The right to erasure (aka the right to be forgotten) is not universal and only applies in certain circumstances. > Let say I use some service, then I violate policies of that company, then I exercise my "right to forget", and after they delete my data I sign up again and repeat the entire thing? In this case a business (or 'data controller' in GDPR lingo) can use 'legitimate interest' as a lawful basis for processing…

That does get complicated in the real world. You might need to retain some data for potential future refunds, for example. But perhaps the application that does refunds also does the loyalty program, and the internals of the app aren't always separate enough that you can delete/obfuscate/whatever info from just the loyalty part.

> You might need to retain some data for potential future refunds, for example.

Then that would be a legitimate interest, and you could store that information for a period of time that is reasonable for processing refund requests.

But you would be barred from using that same information for a different purpose, e.g. the loyalty program.

GDPR article 25 requires systems to be have privacy built in, so a system such as the one you describe where a separation of these concerns is impossible, would probably itself be in violation of the regulation.

Post reply on HN