Live data from Hacker News

How GDPR Will Change The Way You Develop

smashingmagazine.com

251–260 of 710 posts

Re: How GDPR Will Change The Way You Develop

#251

Earlier quoted context omitted.

So if I ignore a law in Canada or the EU (extradition request, default judgement, etc) as an officer of a corporation, I wouldn't get arrested when I show up on the border? Really?

For ignoring the GDPR as a small business owner operating on the internet the chances of individual consequences are nil. High profile cases would have a much higher risk and companies that went out of their way to advertise the fact that they are going to break the law would run a significant risk. Show me just one example of a company located outside the EU without a legal presence inside the EU that had an executi…

Does the EU have any other extra-territoral law as far reaching as the GDPR? Or any other extra-territoral law? A business shipping something to the EU doesn't count.

The only other extra-territorial laws I know of currently is FATCA and the FCPA, which are from the USA.

Re: How GDPR Will Change The Way You Develop

#252
post #214

I really don't think (and I am developer, I will need to comply) that anything in GDPR is hard to understand. Treat data from others in same way as you would treat (and you are treating) yours. You are not selling your personal details to 3rd parties, you are not keeping painfull pictures of yourself climbing to garbage bin and doing diving completely drunk, you are not storing them into pastebin or unsecured databas…

The problem is you are required to prove that you follow the rules, which would take your effort and your money. This is a "guilty until you prove you are not" thing.

Re: How GDPR Will Change The Way You Develop

#253
post #137

I built an app that displays geolocations of tweets on an OpenStreetMap. That data is publicly available from Twitter and users share their location willingly, I presume. Will an app like that become illegal, as far as European tweeters are concerned?

It's unclear. The GDPR definitely covers personal data even if publicly available , so just because you grabbed it from twitter doesn't make it kosher. That said, realistically, I'd have a hard time imagining you would have too much difficulty as long as you allowed people to delete their data upon request. If they post something to twitter, the obvious intent is to make it very public.

For a real life example, there is a group of people that collect Facebook posts and process them through a ML filter which judges if the post contains hate speech, and if it does, it reports the post to the police, supposedly after manual review.

Does this processing comply with GDPR? I'm pretty sure none of the people would allow this processing to take place if they were asked for permission.

Re: How GDPR Will Change The Way You Develop

#254

Earlier quoted context omitted.

I thought that was needlessly snarky. I'm pretty sure other fields rely on lawyers to know the relevant legal landscape just like we do.

> I'm pretty sure other fields rely on lawyers to know the relevant legal landscape just like we do. I have plenty of friends and relatives who work in construction or architecture and knowing the building codes and everything related to it is something you learn at university, update every year and is something every person involved in planning and constructing a building is aware of. Lawyers only get involved if a…

Unlikely. Lawyers are an invisible hand, always present.

They’re the ones who prepare the trainings for your relatives and the other architectural students, or at the minimum the changes that a policy-wonk will react to when creating curriculum.

The site operator has the limited range to act (we’ll call them decision rights) under the CEO who is ultimately guided by his counsel (firm or in-house).

Lawyers also oversee zoning, permitting, and certifying every step of the way - not limited to, but including licensing and contracting.

Re: How GDPR Will Change The Way You Develop

#255

Earlier quoted context omitted.

The GDPR does not require deletion of all user data on request. There’s still data that can and must be preserved, for example business records, thus records of sale. A recall should be possible with those records. The customer might request that these records cannot be used for unrelated purposes, though.

What if the user requests to be put on a do-not-send list (for email newsletters, etc)? Is that data that can and must be preserved?

You’re generally allowed to keep data that is required to provide a service. So in my understanding, yes, if you provide such a service and the user requests that, you should generally be allowed to keep that info _for exactly that purpose_ You can’t use it for anything else though.

Re: How GDPR Will Change The Way You Develop

#256
post #245

Earlier quoted context omitted.

What you do or do not do should not be grounded in the consequences that you will face but in what's the best for your users. If you feel that your users rights are of no concern to you then you are of course entirely able to ignore this law and to pretend it does not exist because in practice there will most likely not be any consequences whatsoever. You do not have a place of business in the EU, you do not transact…

> What you do or do not do should not be grounded in the consequences that you will face but in what's the best for your users. I agree with the above. I disagree however that "what's best for your users" is universally a superset of GDPR regulations. My personal view is that if your company/service becomes so powerful that people can't escape from its influence, the above regulations are a necessary evil in order to…

> It helps to put yourself in others' shoes, and ask yourself how much time/energy you, as a startup founder, would be willing to put into regulatory compliance with Canadian/Russian/Indian laws.

If I were to target my business at Canadians, Russians or Indians I would definitely make an effort to comply, especially if those laws in general did not originate from protectionism or were particularly hard to implement (which I don't think the GDPR is, at least not in spirit).

Re: How GDPR Will Change The Way You Develop

#257

Earlier quoted context omitted.

Not all organisations will need to be compliant with GDPR. By that I mean, if your organisation only do marketing in, for example, the US and Canada, only accepts USD/CAD and they are no legitimate appearance that you do/want to do business in Europe, you are not required to be GDPR compliant, even if an european customer goes on your website and purchases a product/service. If your website accepts Euros, has multipl…

Is that interpretation or is there actually language to this effect in the regulations?

I found this (which is not official or legal advice but does quote the regulation): https://www.gdpreu.org/the-regulation/who-must-comply/

Re: How GDPR Will Change The Way You Develop

#258
post #214

I really don't think (and I am developer, I will need to comply) that anything in GDPR is hard to understand. Treat data from others in same way as you would treat (and you are treating) yours. You are not selling your personal details to 3rd parties, you are not keeping painfull pictures of yourself climbing to garbage bin and doing diving completely drunk, you are not storing them into pastebin or unsecured databas…

lol you think people treat others they way they'd like to be treated...(pardon my childish language)

Re: How GDPR Will Change The Way You Develop

#259

Earlier quoted context omitted.

For ignoring the GDPR as a small business owner operating on the internet the chances of individual consequences are nil. High profile cases would have a much higher risk and companies that went out of their way to advertise the fact that they are going to break the law would run a significant risk. Show me just one example of a company located outside the EU without a legal presence inside the EU that had an executi…

Does the EU have any other extra-territoral law as far reaching as the GDPR? Or any other extra-territoral law? A business shipping something to the EU doesn't count. The only other extra-territorial laws I know of currently is FATCA and the FCPA, which are from the USA.

The GDPR is not an extra-territorial law. It merely concerns itself with EU citizens.

Re: How GDPR Will Change The Way You Develop

#260
post #177
post #81

Earlier quoted context omitted.

No. Professionals in engineering or the trades have to know the regulations that govern their industry and abide by them. What many SVers call "innovation", other industries would call "reckless". How embarrassing for us! EDIT: In terms of regulation, we're practically chiropractors.

The comparison is disingenuous. The internet makes anything you build automatically global. You're blasting software engineers for not knowing worldwide regulations. How many New York lawyers know the regulations of France? How many local UK construction companies know the building codes of Japan? None. Knowing all regulations in the world for any given industry would be a full time job. The people you seem to be imp…

Your reasoning sounds like an easy excuse to not bother looking at any regulations period. Because knowing every single regulation is too onerous and you probably know all your local ones intuitively, right?
Post reply on HN