Live data from Hacker News

How GDPR Will Change The Way You Develop

smashingmagazine.com

91–100 of 710 posts

Re: How GDPR Will Change The Way You Develop

#91

What's troubling to me is that it's very unclear what specifically is required. I know the linked post isn't legal advice, but in the page about 'privacy by design' linked to by the origin link, they list "Minimize the amount of collected data" as as an item (supposedly to be achieved to be in compliance with the law). What's the minimum amount of data? Who decides that? Is it dependent on context? I'd hope so! Can a…

> ...they list "Minimize the amount of collected data" as as an item (supposedly to be achieved to be in compliance with the law).

> What's the minimum amount of data? Who decides that? Is it dependent on context? I'd hope so!

The GDPR says when you collect data, you have to tell the user what you intend to use it for. "Minimization" applies within the context of those stated uses. So if your business purpose is to mail something to the customer, full physical address is OK to collect. If your business purpose is to help them find a nearby store location, you may be expected to collect something less granular like ZIP code or metro area, depending on how many locations you have.

As a corollary, if you can't link a piece of data to a business use, you shouldn't be collecting it. This was a good idea before, but GDPR makes it more relevant.

Note that this is similar to the ethical guidelines for medical research. "Harm Minimization" is a central pillar of ethical research. Harm, and risk of harm, is acceptable, but there is an affirmative duty to seek the least-harmful means of achieving your goal from those available.

> That's a really unsettling description of a law.

That's how HIPAA works, actually. I have a professor who argues this model of legislation is more effective than traditional sector-specific regulation, because it puts the onus of subject-matter expertise onto the people who are actually subject-matter experts, and because it allows for creative and adaptive solutions.

Re: How GDPR Will Change The Way You Develop

#92
post #81

Earlier quoted context omitted.

No. Professionals in engineering or the trades have to know the regulations that govern their industry and abide by them. What many SVers call "innovation", other industries would call "reckless". How embarrassing for us! EDIT: In terms of regulation, we're practically chiropractors.

A lot of what you might call 'avoiding recklessness' is demonstrably bad for some people so it's not clear that the current tradeoffs are optimal . And it's not at all obvious that, overall, regulation does much more than protect incumbents in a given field or industry at the expense of everyone else. Based on my own experience, I've 'known' about regulations that governed the industries with which I've worked. I'm n…

> A lot of what you might call 'avoiding recklessness' is demonstrably bad for some people

And? Making sure that the bridge will hold under the weight that its required to is demonstrably bad for my profits (if I were the construction company). That doesn't mean that we should loosen the regulations or whatever. We don't owe anyone the right to profits, regulations are meant to protect us and keep the playing field fair. Of course that will always negatively affect someone.

Re: How GDPR Will Change The Way You Develop

#93
post #24

"The extraterritorial nature of these two frameworks..." I've noticed that this is something the EU has tried to do lately, to just sort of push their regulations on the rest of the world. I don't see what sort of authority they'd have to impose this on citizens of other countries. I wonder if Europe pushes the issue, if this will be treated like libel tourism, where US citizens and companies without a Eurpoean nexus…

The GDPR applies to transactions with a nexus in the Union. If a US or Chinese traveler books a hotel in Germany, the GDPR protects their data. If a Chinese hotel chain offers a room to a German guest, the GDPR applies to processing of that guest’s data, even if the chain has no other presence in the Union. If that chain stays out of EU data protection agency reach, enforcement is a non-issue. But if Germany and Chin…

> If that chain stays out of EU data protection agency reach, enforcement is a non-issue. But if Germany and China were to enter a bilateral agreement (as the US will).

this is a very good point actually, GDPR will probably also be used in trade agreements as a requirement, in which the EU has a lot of leverage compared to most other nations/trading blocks across the world.

In the end, the reason the EU can do it is simply because it has enough political leverage to make this happen.

edit: To add to this, I think these kind of things will be good in the long run, especially when the EU starts more trading talks with smaller nations, which are usually very eager to get into a trade agreement with the EU, especially for african nations as it usually allows more ways for legal migration and includes foreign aid a lot of the times.

Re: How GDPR Will Change The Way You Develop

#94
post #77

Earlier quoted context omitted.

Are you mixing up ‘personal data’ and ‘personally identifiable information’ (a US legal concept that differs from the EU definition of personal data)?

No, I am simply using shortened text not the USA PII legal concept. GDPR has many more restrictions than the USA concept of PII.

To me it seems quite simple, if the information can be used to identify user it is personal information and you need explanation why you need it and opt in. If this is a problem for you, maybe avoid collecting what you don't need. The idea of "collect everything and audio & canvas fingerprint them, maybe I will need it later" wont pass, you will never get consent. Collect only what you really need.

Re: How GDPR Will Change The Way You Develop

#95
post #91

What's troubling to me is that it's very unclear what specifically is required. I know the linked post isn't legal advice, but in the page about 'privacy by design' linked to by the origin link, they list "Minimize the amount of collected data" as as an item (supposedly to be achieved to be in compliance with the law). What's the minimum amount of data? Who decides that? Is it dependent on context? I'd hope so! Can a…

> ...they list "Minimize the amount of collected data" as as an item (supposedly to be achieved to be in compliance with the law). > What's the minimum amount of data? Who decides that? Is it dependent on context? I'd hope so! The GDPR says when you collect data, you have to tell the user what you intend to use it for. "Minimization" applies within the context of those stated uses. So if your business purpose is to m…

> The GDPR says when you collect data, you have to tell the user what you intend to use it for.

Then that part is worthless, just another click-through "agreement" practically nobody reads.

That part won't change anything.

> So if your business purpose is to mail something to the customer, full physical address is OK to collect. If your business purpose is to help them find a nearby store location, you may be expected to collect something less granular like ZIP code or metro area, depending on how many locations you have.

I always wonder one thing: Is the penalty going to be high enough to justify not breaking this law?

All business decisions are cost-benefit. If the costs of doing something outweigh the benefit, you don't do that. This includes following the law: If you can reliably get more money by breaking the law, you break the law, and pay the penalty if you get caught. Unless you're very unlucky, you're still right-side-up after you pay the penalty, so your behavior was, on the whole, justified.

Re: How GDPR Will Change The Way You Develop

#96

What's troubling to me is that it's very unclear what specifically is required. I know the linked post isn't legal advice, but in the page about 'privacy by design' linked to by the origin link, they list "Minimize the amount of collected data" as as an item (supposedly to be achieved to be in compliance with the law). What's the minimum amount of data? Who decides that? Is it dependent on context? I'd hope so! Can a…

> What's the minimum amount of data? Who decides that? Is it dependent on context? I'd hope so!

You decide, based on context and consent. I think consent now needs to be non-blanket.

> That's a really unsettling description of a law

I know it's not ideal, but it's far from the only vague area. The law of negligence is very important to anyone running a business and is almost entirely caselaw, for example.

It's also a lot like CE certification, which takes a while to get your head around but is similarly based around both standards and self-certification.

Re: How GDPR Will Change The Way You Develop

#97

I’d love to understand GPDR but this article isn’t helping. Can anyone suggest something more focused and direct?

https://www.eugdpr.org/more-resources-1.html

(links to actual text at http://data.consilium.europa.eu/doc/document/ST-5419-2016-IN... )

Re: How GDPR Will Change The Way You Develop

#98

"The extraterritorial nature of these two frameworks..." I've noticed that this is something the EU has tried to do lately, to just sort of push their regulations on the rest of the world. I don't see what sort of authority they'd have to impose this on citizens of other countries. I wonder if Europe pushes the issue, if this will be treated like libel tourism, where US citizens and companies without a Eurpoean nexus…

As came up last time, this is the mirror image of the way the US treats anyone anywhere in the world running a gambling website.

Re: How GDPR Will Change The Way You Develop

#99
post #52

In this article the author states: "The latter definition is important for developers. It includes things like IP addresses, mobile device IDs, browser fingerprints, RFID tags, MAC addresses, cookies, telemetry, user account IDs, and any other form of system-generated data which identifies a natural person.". This information does NOT automatically qualify as personal data. Information being unique is not the same as…

This doesn't make sense to me. Wouldn't that make every id that is one to one or one to many with a customer PII? That seems absurd.

A user alias on some random site would meet that criteria, assuming they took name/address/etc when you signed up.

Unless PII has some other significance than I'm interpretting it to have?

Re: How GDPR Will Change The Way You Develop

#100
I am curious, if you offered a service that allowed users to post their own data to your service. How do you protect against customers posting data that violates the GDPR. I.e. peoples personal information being posted in plaintext?

Is this type of case covered by the GDPR?

Also how are things like access logs supposed to handled according to the GDPR? Our software records all requests made to our API, they log your userid, ip address, and what you were trying to do.

We have clients who are in the US who required the above feature for auditing purposes.

Post reply on HN