Live data from Hacker News

GDPR and Google Analytics

adactio.com

1–10 of 130 posts

Re: GDPR and Google Analytics

#3
GDPR is coming really soon, but it's still unclear how "Big Data companies" prepare to it from technical perspective. In addition to "getting consent" requirement there are "the right to be forgotten" and "the right of access", and it's not obvious how implementing these two are feasible or, at least, cost effective.

Re: GDPR and Google Analytics

#4
It might be an unpopular opinion here, but I'm not entirely sure that the GDPR is going to be a good thing. It seems strange to me to have this enforcement of policies from countries that are not my own just because my website is accessible from those countries.

On top of that, developing business software becomes incredibly complex when navigating all of the potential ramifications of these policies. I thought it was strange that the SAP SDK at a hackathon essentially required the app to get OAuth permission from the user to access / write an encrypted payload that the app couldn't read / access / delete / update without user consent.

Re: GDPR and Google Analytics

#5
well.. yes. super useful those google analytics. but maybe it is making things to easy for you :)

if you come to think of it, it is also a privacy nightmare.. therefore google analytics is blocked by my Privacy Badger!

Re: GDPR and Google Analytics

#6
> This regulation is not limited to companies based in the EU—it applies to any service anywhere in the world that can be used by citizens of the EU.

That's fundamentally incorrect. As a non-EU citizen, I reject the notion that a foreign government has the right to impose their own laws on me, be it the EU or China or anyone else. If the EU thinks it's a problem that I'm offering a service to EU citizens that doesn't comply with laws I have no vote on, frankly they can sod off.

Re: GDPR and Google Analytics

#7
post #6

> This regulation is not limited to companies based in the EU—it applies to any service anywhere in the world that can be used by citizens of the EU. That's fundamentally incorrect. As a non-EU citizen, I reject the notion that a foreign government has the right to impose their own laws on me, be it the EU or China or anyone else. If the EU thinks it's a problem that I'm offering a service to EU citizens that doesn't…

It being fundamentally incorrect and you not liking it are two very different things.

Re: GDPR and Google Analytics

#8
post #6

> This regulation is not limited to companies based in the EU—it applies to any service anywhere in the world that can be used by citizens of the EU. That's fundamentally incorrect. As a non-EU citizen, I reject the notion that a foreign government has the right to impose their own laws on me, be it the EU or China or anyone else. If the EU thinks it's a problem that I'm offering a service to EU citizens that doesn't…

Yes, it's your right to block the EU users. But, if you want their money (and that's up to you to decide), you have to obey to their law, nothing new here.

Re: GDPR and Google Analytics

#9
post #8
post #6

> This regulation is not limited to companies based in the EU—it applies to any service anywhere in the world that can be used by citizens of the EU. That's fundamentally incorrect. As a non-EU citizen, I reject the notion that a foreign government has the right to impose their own laws on me, be it the EU or China or anyone else. If the EU thinks it's a problem that I'm offering a service to EU citizens that doesn't…

Yes, it's your right to block the EU users. But, if you want their money (and that's up to you to decide), you have to obey to their law, nothing new here.

It's not their money, it's if you store or process personal data about individuals in the European Economic Area (slightly larger than the EU).

If you're running a Chinese site aimed at Chinese you're good.

If you're running an Indonesian site aimed at Germans you need to honour the GDPR.

Re: GDPR and Google Analytics

#10
My problem with the GDPR is the EU can't even be bothered to tell us what it is before the effective date. And the GDPR itself is quite vague; lots of balancing tests and blah blah with very little guidelines on what those mean in practice. So where do the guidelines come from? Funny you should ask.

Consider the ICO -- the UK privacy commission -- has been promising final GDPR guidance for perhaps half a year now, and instead are sitting around with their thumbs up their asses waiting on the Article 29 Working Party final guidance. The Article 29 Working Group held comments open until 23 January 2018. Some unknown amount of time later, that working group will finalize, and then some unknown amount of time later, the ICO will issue their guidance.

But don't you worry, the ICO plans to offer no grace period to us!

How the hell organizations are supposed to be ready by 25 May when they may receive final guidance in late February is a hell of a question. Realistically, considering the ICOs adherence to deadlines so far, they're gonna deliver their final guidance promptly for May 2019.

I'm essentially assuming users will be hit with a blizzard of opt-in dialogues.

One of the few things in the GDPR that will have impact is if you use consent as a legal basis for processing, everything has to be default opt-out.

Post reply on HN