Live data from Hacker News

GDPR and Google Analytics

adactio.com

81–90 of 130 posts

Re: GDPR and Google Analytics

#81
post #74
post #55

Earlier quoted context omitted.

No, you're confused. Google has a physical presence and business partners in Europe; I do not. (Profiting from EU citizens is beside the point.)

Yeah, but what would you do if the EU decides that you cannot sell your product in the EU?

I would continue to do nothing special to support the EU's provincial laws. If EU citizens want to send me money, fine. If the EU decides to block its citizens from doing so, that's also fine.

But I will take no actions on my end to implement EU laws, and it's laughable that some people in this thread imagine the EU has the power to coerce me to do so.

Re: GDPR and Google Analytics

#82
post #25
post #15

Earlier quoted context omitted.

You don't need any personal data to conduct most of the business. I work in a place that would be beyond heavily affected by GDPR and I find the legislation a good change as companies should not hoard data they don't need - just in case... or just to sell.

Wouldn't you need personal data to accept payments? Or maybe a broker (like Stripe) would store these and the end business just a reference to payment.

You can get external ref to payment providers. Depending on the business you might need KYC and anti laundering procedures and then it's harder.

However if you have some direct business and do accept payments - by all means make it secure and transparent to your customers.

Re: GDPR and Google Analytics

#84

I got a speeding ticket in Germany last year. I want them to delete my record. I own the data, they just tracked me over-speeding.

Data retention policies in GDPR specifically address the case, if there is a legal reason to keep the data it should take precedence. That's it you can't tell that you wish your 10k euro bank credit to be forgotten.

Accounting logs might need to be kept up to seven (in some cases 10) years, so the data related to them should be kept. The data is sort of field based and some might need to be able to be forgotten earlier.

Re: GDPR and Google Analytics

#85
post #77
post #57

Earlier quoted context omitted.

Exactly, that's the distinction.

What is your website? And which bank do you happen to use for your company and personally? Enforcing laws internationally is easy, considering that there are systems designed to allow the police of one country to freeze the assets of citizen of another country. You might just wake up one morning with your bank accounts frozen and your credit cards revoked if you violate the GDPR. Governments have previously seized en…

> You might just wake up one morning with your bank accounts frozen and your credit cards revoked if you violate the GDPR.

Please, spare me. I'm no more worried about EU laws than I am about China seizing my accounts for mentioning Tiananmen Square. You overestimate the EU's reach.

Re: GDPR and Google Analytics

#86
post #62
post #31

Earlier quoted context omitted.

Uh? This is already how the world works. It does not matter where you are located as long are you are transacting with EU citizens. In extreme cases of non-compliance, avenues for enforcement that have been discussed reuse existing Anti Money Laundering mechanisms: once flagged in the system, banks will simply freeze your business assets connected to EU countries and you might be arrested upon crossing any EU border.

I have no business assets connected to any EU countries, and I don't have any desire to cross any EU borders. So I will continue to enjoy life in my home country and ignore your provincial laws.

So why are you so nervous? Just ban all those 500 millions "provincial" users and feel free to ignore GPDR. It's nothing new that countries extend protection for their citizens and business entities well beyond its borders, for example, US routinely extradites foreign citizens that have nothing to do with USA for DMCA violations, hacking and whatnot.

Re: GDPR and Google Analytics

#87

I got a speeding ticket in Germany last year. I want them to delete my record. I own the data, they just tracked me over-speeding.

And sure, by German law, your data will be deleted after you paid your fine. (Plus some time for processing and record keeping)

This doesn’t make this a good analogy though. The GDPR does not prohibit storing private data, it just requires explicit and informed consent. It does not require deletion of data that is required to conduct a transaction, such a receipts, order data or adresses required to fulfil an order. It doesn’t impact storage of data required for law enforcement or any other reason that is mandated by law. It just doesn’t allow unconsentual tracking and accumulation of private data.

Re: GDPR and Google Analytics

#89
post #70
post #35

I hope everyone is nice and busy setting up encryption, access control and timely erasure for all their server and application logs: https://www.ctrl.blog/entry/gdpr-web-server-logs

The article is full of misunderstandings. The following sentence for example is just wrong: 'You can’t collect and store any personal data without having obtained, and being able to document that you obtained, consent from the persons you’re collecting data from.' Consent is just one option. You can do logging without personal data. You might have a legal obligation do to (full) logging. You might have a legitimate i…

Your comment does clarify the issue by pointing out the alternative, and the article could have mentioned that, but the quoted sentence is completely correct as quoted. It fails to mention the alternative, but there's nothing actually wrong in the statement.

I'll give you that the article is not very comprehensive, but the GDPR is large and complex and the author doesn't set out to cover it in every detail. What misunderstandings did you see?

Re: GDPR and Google Analytics

#90
post #4

It might be an unpopular opinion here, but I'm not entirely sure that the GDPR is going to be a good thing. It seems strange to me to have this enforcement of policies from countries that are not my own just because my website is accessible from those countries. On top of that, developing business software becomes incredibly complex when navigating all of the potential ramifications of these policies. I thought it wa…

> It seems strange to me to have this enforcement of policies from countries that are not my own just because my website is accessible from those countries. If you open shop in a different country, you follow their laws. Your website being accessible in a country is seen as the same thing. It's not hard to implement geo blocking if you want to show best effort and thereby opt out of it.

This can very quickly become onerous for anyone wanting to run a website, if they have to understand the law of any country where it might be accessed. I think the onus of geoblocking should be in the country that decides this website doesn't obey it's laws, otherwise only large corporations with lawyers will be able to run websites.

If your website is doing business (i.e. Has some sort of legal presence) in another country, well, that's a different story.

Post reply on HN