Live data from Hacker News

How GDPR Will Change The Way You Develop

smashingmagazine.com

221–230 of 710 posts

Re: How GDPR Will Change The Way You Develop

#221
post #202
post #86

Earlier quoted context omitted.

So nice to see progress in privacy but please someone explains how GDPR will help EU startups! GDPR is inevitably going to hinder any new company forced to abide by it. So the next Uber/Wechat will first flourish in US/China/Russia and then come to the EU, not the other way around. Entrepreneurs / investors also want their time & money to be used to build value first rather than solve yet another accidental complexit…

Let's say you're a business in the EU that needs a sales management system. In it, you store personal data of your clients. You are considered a "controller"; the SaaS sales management system (that will store this data for you) is considered a "processor." GDPR states that to remain compliant, Controllers must only use GDPR-compliant Processors.[1] Assuming that EU startups will take GDPR more seriously than non-EU c…

> Assuming that EU startups will take GDPR more seriously than non-EU companies

It’s also easier in terms of jurisdiction. A non-EU company might just pretend they’re compliant but your legal options in case they’re not are somewhat limited.

Re: How GDPR Will Change The Way You Develop

#223
post #210

Funnily, one of the common fears our clients ( https://gdpr-tools.eu ) have with regards to GDPR is not about the general public. It comes from disgruntled employees ratting on the company. Employees know best where personal data is stored (and often no one else in the company does), so they can really do some surgical damage by reporting their employer to the "authorities". GDPR introduces a whole new dynamic.

This is the case for every law. A disgruntled[1] employee at a coffee shop that has mold growing on the kitchen ceiling can, after being ignored by management for weeks, rat on the company. (And then get shitcanned, with no recourse, because none of their co-workers will testify to the truth on their behalf, because they are cowards who don't want to lose their jobs. Understandable, but sad.)

This doesn't mean that we don't need food health and safety inspection laws. It does mean that you actually need to run your business in a way that respects your customers.

Stop running your company with the attitude of "It's fine, as long as I can get away with it." I have no sympathy for that.

[1] You can be a disgruntled employee, and also be 100% in the right, if your boss is behaving illegally.

Re: How GDPR Will Change The Way You Develop

#224

Is it just me or does this article manage to give advice while saying nothing at all about what is required? For example: > The first half is the General Data Protection Regulation (GDPR), which becomes enforceable across Europe on 25 May 2018. This is an overhaul, modernization, and replacement of the existing framework, the Data Protection Directive of 1995 (yes, 1995.) > All of the existing principles from the ori…

You could simply go and read the GDPR text. It's actually ok. Compared to say the Verified-by-VISA spec :)

Re: How GDPR Will Change The Way You Develop

#225
post #214

I really don't think (and I am developer, I will need to comply) that anything in GDPR is hard to understand. Treat data from others in same way as you would treat (and you are treating) yours. You are not selling your personal details to 3rd parties, you are not keeping painfull pictures of yourself climbing to garbage bin and doing diving completely drunk, you are not storing them into pastebin or unsecured databas…

Yeah, but isn't it possible to trivially and inadvertently combine a bunch of systems S1 ... Sn which are all respecting the GDPR into a new system which doesn't?

We will see, new regulation is coming after GDPR and I bet they will plug the missing holes there. There was a cookie law that everyone circumvented. Now the same people are complaining about GDPR. The next round is going to put even more restrictions, and the regulation is going to be blamed. But the ones to be blamed are the ones who abuse it.

Re: How GDPR Will Change The Way You Develop

#226

Earlier quoted context omitted.

Imagine the EU made a law requiring every country in the world follow their building codes whenever an EU citizen enters one of their buildings, even if the building was made before the law was created. And if you don't comply, they will fine you millions of dollars. McDonalds goes and retrofits all of their buildings in the world because they have shops in the EU at great cost. Some pizza shop that does delivery in…

> Imagine the EU made a law requiring every country in the world follow their building codes whenever an EU citizen enters one of their buildings You are reaching. I give you a better example: it does not matter where a building part is being produced, if it ends up in a building in Europe it needs to be up to the local building codes and to the regulations of the single market.

You think I am reaching, but the GDPR does act this way.

Lets say your visiting the USA as an EU citizen and you get a pizza delivery from a local small pizza shop. They put your name and delivery address in their computer in an MS Access database that makes stickers, emails the delivery guy's gmail account and a person delivers a pizza to you.

They have no idea your an EU citizen and they just put enough information into their computer that would violate the GDPR. They have no real way to comply unless they retrofit their computer system to some vendor that is GDPR compliant, if it even exists. Just deleting your info from the msaccess db and asking the delivery guy to delete their emails isn't enough for the GDPR. And a computer system retrofit for most business might as well be like asking them to retrofit their building as far as costs go.

The end effect might be just outright banning all EU citizens from doing business with various places, because it's just not worth the hassle.

'Sorry you cant stay at our hotel, we are not GDPR compliant'

'Sorry we won't deliver to you, we are not GDPR compliant'

'Sorry you can't enroll in our classes, we are not GDPR compliant'

'Sorry we won't treat you at this hospital, we are not GDPR compliant'

'Sorry you can't get a bank account with us, we are not GDPR compliant' (Like a lot of EU banks with US citizens with FATCA)

Re: How GDPR Will Change The Way You Develop

#227
post #153

What's troubling to me is that it's very unclear what specifically is required. I know the linked post isn't legal advice, but in the page about 'privacy by design' linked to by the origin link, they list "Minimize the amount of collected data" as as an item (supposedly to be achieved to be in compliance with the law). What's the minimum amount of data? Who decides that? Is it dependent on context? I'd hope so! Can a…

> What's the minimum amount of data? Who decides that? Is it dependent on context? I'd hope so! Elizabeth Denham, UK's information commissioner in charge of data protection enforcement, had this to say: "Having larger fines is useful but I think fundamentally what I'm saying is it's scaremongering to suggest that we're going to be making early examples of organisations that breach the law or that fining a top whack i…

> A practical trouble is that once a company reaches a certain size, they no longer even know what data they have, never mind why.

That's a very good reason to do a little inventory then. Not knowing what data you have is a real problem in my book.

Re: How GDPR Will Change The Way You Develop

#228
post #2

Im surprised this place is called "hacker" news and iid actually filled with privacy conscious people but nobody bats an eye about not being able to delete comments. I have to create new accounts every so often to avoid being doxxed by the alt-right.

I'm kind of curious to find out what kind of comments you're publishing on Hacker News, of all places, that's making you a target to the alt-right.

It's not "hacker" news you monkey with a keyboard. If it were you'd be able to delete your comments. Also alt-right and Russia are everywhere and very dangerous

Re: How GDPR Will Change The Way You Develop

#229

What's troubling to me is that it's very unclear what specifically is required. I know the linked post isn't legal advice, but in the page about 'privacy by design' linked to by the origin link, they list "Minimize the amount of collected data" as as an item (supposedly to be achieved to be in compliance with the law). What's the minimum amount of data? Who decides that? Is it dependent on context? I'd hope so! Can a…

You have discovered the difference between principles-based regulation and rules-based regulation .

Re: How GDPR Will Change The Way You Develop

#230
post #134

Suppose you were a small startup based in America, accepting online payments from users/advertisers using American platforms or financial institutions. Suppose you make no effort to comply with GPDR - what realistic consequences can you face? I suspect that this is the kind of thing which larger/established companies would worry about. If you're a seed/series-A startup, it seems like you have far more important thing…

If you're consumer focused, you're probably fine and will just need to clean up some mess later when you get big enough to care.

If you're B2B, it's going to be a problem from day one. GDPR has a defacto viral component for service providers. Basically, any the business that wants to become your customer that is itself GDPR compliant needs to ensure that you too are GDPR compliant. Accordingly, GDPR will come up with a large portion of web-facing B2B sales, even for US companies.

Post reply on HN