Live data from Hacker News

Tech Giants Brace for Europe’s New Data Privacy Rules

nytimes.com

41–50 of 55 posts

Re: Tech Giants Brace for Europe’s New Data Privacy Rules

#41
post #35
post #27

Earlier quoted context omitted.

Hindering the kind of innovation that violates the citizen's privacy is pretty much the point of the law. A company having a database of my mental health status is incredibly creepy to me. As is the facial recognition thing.

There is a lot of good that can come out of a database on the mental health of a large population. I think you should be able to opt out of such collection but I'm not in favor of banning such collection altogether.

Realistically, the benefits are better ad targeting and improved addictiveness of the platform. Iotw, no benefit for me.

Sure in the best case you can do a lot of good with such data. But that would probably need the data to be open to researchers, not in some corporate silo somewhere.

And in the worst case, pervasive surveillance data can do a lot of harm. Just ask yourself what an organization like the Stasi could have done with that kind of data.

Re: Tech Giants Brace for Europe’s New Data Privacy Rules

#42
post #35
post #27

Earlier quoted context omitted.

Hindering the kind of innovation that violates the citizen's privacy is pretty much the point of the law. A company having a database of my mental health status is incredibly creepy to me. As is the facial recognition thing.

There is a lot of good that can come out of a database on the mental health of a large population. I think you should be able to opt out of such collection but I'm not in favor of banning such collection altogether.

It should be opt-in.

Re: Tech Giants Brace for Europe’s New Data Privacy Rules

#43

On the one hand this may help certain companies that focus on limited use of customer data thrive in Europe. On the other hand it’s one more tick against Europe for global companies deciding where to invest so expect to see some big downside for the region too as companies and investors focus elsewhere.

Don't forget the EU represents the worlds largest economic area [1], with a population of over 740 million (compared to the US's 320 million). Although it's small compared to China's ~1.4 billion.

And the of course the big advantage that the EU has over other clusters of countries is the (mostly) unified legal and regulatory system. Which makes it easy to target every country in the EU at the same time.

I think the EU has had a lot of soft-power for a very long time, and we are finally starting to see it flexing that power to protect it's citizens.

[1]. http://ec.europa.eu/trade/policy/eu-position-in-world-trade/...

Re: Tech Giants Brace for Europe’s New Data Privacy Rules

#44
post #11

Good time to be a contractor who knows about GDPR compliance

In what way? Genuinely curious - what sort of technical work needs to be done that requires actually knowing the regulation? I'm asking because I got my law degree with the idea that I would combine tech skills with knowledge of the law, but I never really found an angle to make that work.

All data now collected directly or indirectly that can identify an individual or is linked to an identified individual now needs careful consideration - do you have explicit consent to collect and use that data for that specific purpose? How is that data stored? Who has access to that data? Can the individual view it, correct it, delete it?

For example your data scientist can't now look at the raw data and decide to feed it into some new machine learning process to identify fraudulent transactions if when the data was collected explicit consent wasn't obtained to do that.

Technical people now need to understand what data is 'protected' by GDPR and what consents have been given for the processing of that data. And that for example linking an IP address to a piece of data can suddenly transform it into personal data now protected by GDPR.

Re: Tech Giants Brace for Europe’s New Data Privacy Rules

#45
As a resident of Europe (now looking rather shaky unfortunately) I'm happy about regulations that force companies to be more responsible with my data.

As a programmer who has to make sure my code and business conform to these regulations it will mean more effort.

Taken together I'd rather have the data protections for me and my family, so on balance I'm happy with the data protection laws in Europe, and the strengthening of them these rules bring in.

Re: Tech Giants Brace for Europe’s New Data Privacy Rules

#46
post #35
post #27

Earlier quoted context omitted.

Hindering the kind of innovation that violates the citizen's privacy is pretty much the point of the law. A company having a database of my mental health status is incredibly creepy to me. As is the facial recognition thing.

There is a lot of good that can come out of a database on the mental health of a large population. I think you should be able to opt out of such collection but I'm not in favor of banning such collection altogether.

GDPR makes things opt-in, it means you have to consent. I fail to see how that is a bad thing.

Re: Tech Giants Brace for Europe’s New Data Privacy Rules

#47

On the one hand this may help certain companies that focus on limited use of customer data thrive in Europe. On the other hand it’s one more tick against Europe for global companies deciding where to invest so expect to see some big downside for the region too as companies and investors focus elsewhere.

Sounds like an advertising problem. "Our company chose to be based in the EU because we comply with all their customer privacy protection laws. Not sure why our competitors chose a country without such laws...."

Re: Tech Giants Brace for Europe’s New Data Privacy Rules

#48
post #11

Earlier quoted context omitted.

In what way? Genuinely curious - what sort of technical work needs to be done that requires actually knowing the regulation? I'm asking because I got my law degree with the idea that I would combine tech skills with knowledge of the law, but I never really found an angle to make that work.

Sounds like with your two skillsets, compliance and/or internal audit would be a good job for you. These jobs often rely on reading legal-ish documents such as HIPAA, PCI, and GDPR and interpreting them for your company's unique situation, then either overseeing the implementation of IT policies or actually implementing the IT policies yourself to control the IT systems appropriately. With internal audit you're gener…

Spot on! I moved from infrastructure engineer to risk management (governance, risk, compliance). You need the technical experience to translate compliance and governance requirements into technical requirements.

Highly recommend the move for anyone who doesn’t want to be on call or carry a pager anymore.

Re: Tech Giants Brace for Europe’s New Data Privacy Rules

#49

I'm wondering how big an opportunity it is for privacy-preserving companies in Europe to take over. I'm thinking of Snips ( https://snips.ai ) for instance, and its "Private by design" voice assistant solution. My guess is that it gives them a good attack angle, but big players like Google an Amazon will comply eventually.

Not one. At least not privacy-preserving. It may be an opportunity for European companies to take over in some narrow segments but that would be due to ordinary protectionism.

The GDPR is not really a law in the conventional sense. It's better understood as a political maneuver. I've been researching it lately as it may affect the company I work for (which has a presence in the EU, well UK, but EU for now).

First problem - the GDPR is so vague that it's impossible to know what it really says, what it bans and what it allows. With just months to go before enforcement begins there are still 50/50 splits amongst legal professionals about basic things like how it affects backup strategies. For instance if someone invokes their "right to be forgotten", do you have to restore and rewrite all backup tapes? Or can you filter out their data at restore time? If not then what if you start getting a constant stream of forget-me requests - do your backups have to be now constantly rewritten and if so, are they still really backups? What about if someone emails you from Europe. You now hold their "personal data", so what if they ask you to delete it? Do you have to erase not just their email but any email that quotes or forwards that email? If so, how exactly can you do that given that no email software supports such a feature? What if you're hosting email and someone emails one of your users, then demands to be forgotten - do you erase their email right out of your users inbox? These are just a few obvious questions of hundreds.

Second problem - the new regulator being set up does not issue binding decisions except in case of cross-border disputes. If you want clarification you're meant to ask local data protection agencies, or the new regulator, but the answers you get back might be wrong, or too vague to be useful, and there's nothing you can do.

Third problem - the potential fines are so vast they could instantly bankrupt most companies. So not only is there a law you can't ever be sure you're in compliance with, because it's so badly written, but if the EU decides you are in violation, that can be the end of your firm.

The cynic in me looks at this terrible low quality law and frankly doesn't see a law at all. He sees a political project - namely a clever way to sidestep the EU treaty's ban on the EU levying a corporation tax. With increasing euroscepticism across the continent the chance of the EU being given direct tax raising powers is now very low, but the EU is stuffed with true believers who want to turn it into a new country ("Europe") that replaces the existing countries. To become the new de-facto government of Europe the EU must be able to fund itself and not rely on member states or their pesky votes .... being able to fund itself by "fining" i.e. taxing foreign tech firms for endless violations of a law they cannot ever hope to understand is an ideal way to do this.

Re: Tech Giants Brace for Europe’s New Data Privacy Rules

#50
post #2

> If companies do not comply, they could face fines totaling 4 percent of their annual revenue. I am curious on how did they arrive at the 4% cap?

I think it was a balancing act. Currently in the UK, the Information Commissioner's Office can fine up to a maximum of £500,000. The concern was that for larger organisations, the cost of compliance with the Data Protection Act (1998) was higher than any potential fine handed out by the ICO. So by placing the limit at 20m Euro, or 4% of annual revenue, they give the legislation adequate 'bite' to persuade boards that…

Do consider that they can also shut down whatever operations they consider to be in violation.

For example, if you're in e-commerce like my previous employer, then having your website/app channels shut down while you implement some bizarre scheme can cost you even more than 4% of your annual revenue. For a big, established company with byzantine operations and large code bases, being caught entirely unprepared can mean a mountain of effort - months - to become compliant.

(And I haven't checked but I imagine it's past year's revenue that is used for the calculation so the double whammy doesn't even get reduced by being shut down.)

Post reply on HN