Live data from Hacker News

How GDPR Will Change The Way You Develop

smashingmagazine.com

41–50 of 710 posts

Re: How GDPR Will Change The Way You Develop

#41
post #17

I will show you another case, company that isnt "bitching" over laws that are good for all humans not just EU and does the right thing, you know backblaze, right? "The changes that are being made by companies such as Backblaze to comply with GDPR will almost certainly apply to customers from all countries. And that’s a good thing. The protections afforded to EU citizens by GDPR are something all users of our service…

Everyone is freaking out. If GDPR is a success Americans may want it too. The same happened with Steam refunds.

Re: How GDPR Will Change The Way You Develop

#42
post #15

Earlier quoted context omitted.

It's quite simple. If you want to do business in the EU or with people who reside in the EU, you need to comply with the EU's regulations. Don't like it? Don't do business in/with the EU. Then you're free to ignore their frameworks, rules and regulations. They are not trying to "impose their regulations on the rest of the world", they're trying to protect the privacy of their inhabitants. That this leads to measures…

If a business decides to opt-out of doing business with the EU as a result, what measures do they need to take? Would a banner asking "Are you an EU citizen? Yes/No" suffice? Or would we have to use some kind of Geo IP tool? How would that defend against EU citizens using a VPN or Tor, and what would a business's liability be in that case?

Not all organisations will need to be compliant with GDPR. By that I mean, if your organisation only do marketing in, for example, the US and Canada, only accepts USD/CAD and they are no legitimate appearance that you do/want to do business in Europe, you are not required to be GDPR compliant, even if an european customer goes on your website and purchases a product/service.

If your website accepts Euros, has multiple european languages (e.g. spanish, german, etc.), you do marketing in Europe, then we can conclude that you legitimely do business in Europe, you are then required to be GDPR compliant. This is indicated in one of the GDPR article (can't remember which one)

Edit: fix typos

Re: How GDPR Will Change The Way You Develop

#43

Earlier quoted context omitted.

It's quite simple. If you want to do business in the EU or with people who reside in the EU, you need to comply with the EU's regulations. Don't like it? Don't do business in/with the EU. Then you're free to ignore their frameworks, rules and regulations. They are not trying to "impose their regulations on the rest of the world", they're trying to protect the privacy of their inhabitants. That this leads to measures…

There's a big difference between "in the EU" and "with people who reside in the EU". When I come to the EU to do business, sure, I'll comply with their laws. But it's very different to expect people who live outside the EU to respect EU laws, just because someone from the EU happens to choose to visit their website. I don't see this as any different than if someone in the EU was to visit a convenience store in the US…

For the same reason that downloading a song is different than stealing with a CD. Digital stuff is innately different.

You aren't doing business unless you're accepting payments/selling/shipping things to people in the EU. And as with any law, if you're sufficiently small fry the EU isn't going to care about you until you actually screw up. Don't accept euros as currency. Don't offer to ship to EU nations. Done. If you do accept payments/ship/etc, unless you're a multinational, the EU probably won't care anyway, as you'll fly under the radar, unless you leak customer information. Do that in a sufficiently extravagant way, and they -will- care, but unless you have assets in the EU they can't/won't do anything about it anyway.

Re: How GDPR Will Change The Way You Develop

#45

Earlier quoted context omitted.

Absolutely! Anybody who does business in Europe or even has users in Europe is subject to this law. The amount of effort being put into GDPR compliance within my organization is just staggering. It really makes me think about these kind of laws from a new perspective, because they cost businesses so much to implement. (I'm not saying whether GDPR is right or wrong! Just that it's expensive.)

I would (maybe naively) think that the cost of GDPR compliance would be small if your company is already safeguarding user data and respecting user privacy. If a company’s cost is “staggering“ doesn’t that say a lot about its existing privacy practices?

I'm not sure. I think this is a very absolutist and probably naive way to look at it, frankly.

For a simple example, let's say you use an immutable data store. What do you do if a customer wants every info about them redacted, but you did something like store their IP, name, or email. All common things. Now you must build mutability into your store and all assumptions that used to be made can be removed.

This is just a very small piece of something that even a small or medium company may be using or doing.

Re: How GDPR Will Change The Way You Develop

#46
post #15

Earlier quoted context omitted.

It's quite simple. If you want to do business in the EU or with people who reside in the EU, you need to comply with the EU's regulations. Don't like it? Don't do business in/with the EU. Then you're free to ignore their frameworks, rules and regulations. They are not trying to "impose their regulations on the rest of the world", they're trying to protect the privacy of their inhabitants. That this leads to measures…

If a business decides to opt-out of doing business with the EU as a result, what measures do they need to take? Would a banner asking "Are you an EU citizen? Yes/No" suffice? Or would we have to use some kind of Geo IP tool? How would that defend against EU citizens using a VPN or Tor, and what would a business's liability be in that case?

Deny access to EU citizens. If EU citizens then lie about their identity its out of your hands.

Re: How GDPR Will Change The Way You Develop

#47
post #26

[ads]If you by chance are storing health/sensitive data and want compliance with GDPR, we actually build https://www.chino.io for that. [/ads] For anything (eg. questions, feedbacks) i'm here.

So here in Sweden (and I imagine a couple other EU countries) there is the Patient Data Law (PDL) that regulates the use of health data.

This will probably have to change a bit with GDPR but will still supersede GPDR when it comes to health data. Are you providing compliance with those laws as well?

Re: How GDPR Will Change The Way You Develop

#48

Earlier quoted context omitted.

It's quite simple. If you want to do business in the EU or with people who reside in the EU, you need to comply with the EU's regulations. Don't like it? Don't do business in/with the EU. Then you're free to ignore their frameworks, rules and regulations. They are not trying to "impose their regulations on the rest of the world", they're trying to protect the privacy of their inhabitants. That this leads to measures…

There's a big difference between "in the EU" and "with people who reside in the EU". When I come to the EU to do business, sure, I'll comply with their laws. But it's very different to expect people who live outside the EU to respect EU laws, just because someone from the EU happens to choose to visit their website. I don't see this as any different than if someone in the EU was to visit a convenience store in the US…

The comparison to the convenience store fails because in the digital realm, the customer does not need to physically travel outside the EU to do business with somebody outside the EU.

Or, to look at it another way: If it weren't extraterritorial, ad providers (for example) could simply close their local branches, and EU citizens would not be protected from consent-less data gathering. To realistically be able to fulfill its mission, the GDPR _has_ to be global in scope.

Re: How GDPR Will Change The Way You Develop

#49

Earlier quoted context omitted.

I would (maybe naively) think that the cost of GDPR compliance would be small if your company is already safeguarding user data and respecting user privacy. If a company’s cost is “staggering“ doesn’t that say a lot about its existing privacy practices?

It says a lot about the cost of privacy, period. The cost would be staggering whether they're modifying existing things, or creating new things, just in terms of ensuring "Yes, we're doing this correctly".

I just find it hard to believe that the law is a significant cost to companies already doing the right thing. Sure, there is a non zero cost to ensuring your existing practices are lawful, which everyone must pay. But companies already in compliance shouldnt have to modify or create anything.

The companies that have to spend significant coin are the ones who are not already complying.

Re: How GDPR Will Change The Way You Develop

#50
post #33

Earlier quoted context omitted.

GDPR is not about money, you may not accept payments at all.

ok, but maybe combined with the notice that if you're from EU, you should leave, that would be an effective measure to show you mean it when you say 'no business with EU'.

Users in the EU are not legally required to follow such notices until you make some form of contract with them. Which requires consent.
Post reply on HN