Live data from Hacker News

How GDPR Will Change The Way You Develop

smashingmagazine.com

261–270 of 710 posts

Re: How GDPR Will Change The Way You Develop

#261
post #214

I really don't think (and I am developer, I will need to comply) that anything in GDPR is hard to understand. Treat data from others in same way as you would treat (and you are treating) yours. You are not selling your personal details to 3rd parties, you are not keeping painfull pictures of yourself climbing to garbage bin and doing diving completely drunk, you are not storing them into pastebin or unsecured databas…

Can you point me to a definitive source as to what websites that have access log that include IP addresses (which is pretty much everyone) have to do to be compliant? If there are steps that must be taken, who has to taken them?

I've been looking, and I have found a bunch of contradictory explanations. My best guess is that if you have a disclaimer that says you log IP addresses for security purposes, you can keep your access logs indefinitely. (see: https://community.spiceworks.com/topic/2041760-access-logs-i...)

This seems like the sort of concern that should be clearly addressed with an official answer before the regulation takes effect.

Re: How GDPR Will Change The Way You Develop

#262

Earlier quoted context omitted.

A lot of what you might call 'avoiding recklessness' is demonstrably bad for some people so it's not clear that the current tradeoffs are optimal . And it's not at all obvious that, overall, regulation does much more than protect incumbents in a given field or industry at the expense of everyone else. Based on my own experience, I've 'known' about regulations that governed the industries with which I've worked. I'm n…

> A lot of what you might call 'avoiding recklessness' is demonstrably bad for some people And? Making sure that the bridge will hold under the weight that its required to is demonstrably bad for my profits (if I were the construction company). That doesn't mean that we should loosen the regulations or whatever. We don't owe anyone the right to profits, regulations are meant to protect us and keep the playing field f…

It isn't obvious that is a case. Some companies make bad short-term decisions. But many take a longer-term view. Who would hire the construction company again that made the bad bridge? Or consider food and drug regulation. Countries with more lax requirements for proof of drug efficacy and large-scale trails don't have worse health outcomes. In fact, the countries with stricter policy regimes are often slower to have receive life-saving drugs. Does the suppression of a drug with adverse effects that only shows up in a wider population or after more prolonged exposure have a stronger benefit than that the suppression of drugs without such downsides? Often countries optimize in the wrong direction here. Many licensing laws fall in this category too. Do barbers and hair stylists need a license? Probably not to ensure safety and we have plenty of comparable jurisdictions with and without such rules to prove it. People don't just start doing bad things in the absence of rules.

Re: How GDPR Will Change The Way You Develop

#263
post #178
post #157

Earlier quoted context omitted.

If your company is not targeting the EU as a market you are out of scope of GDPR. If you explicitly accept Sterling/Euros, provide localisations for EU countries, talk explicitly about your EU shipping options etc. then you would probably be seen as accommodating the EU market and might find yourself in scope.

Consider the case of an EU citizen traveling in the US transaction in USD. This person is covered. Even if they are in the US.

This is exactly what I was coming to HN to query about. Without some agreement with the US federal government, I don't believe they would have any mechanism of enforcement that would affect your business in the U.S. I imagine they could do something like block your site from EU ip addresses but nothing like coming after you or your company for damages.

Re: How GDPR Will Change The Way You Develop

#264

Earlier quoted context omitted.

You think I am reaching, but the GDPR does act this way. Lets say your visiting the USA as an EU citizen and you get a pizza delivery from a local small pizza shop. They put your name and delivery address in their computer in an MS Access database that makes stickers, emails the delivery guy's gmail account and a person delivers a pizza to you. They have no idea your an EU citizen and they just put enough information…

> Lets say your visiting the USA as an EU citizen and you get a pizza delivery from a local small pizza shop If that pizza store has no relation to the EU then there is no legal ground by which the GDPR could become relevant. There is no treaty which would establish some sory of leverage here. //EDIT: which btw is unlike FATCA for which there actually are bilateral agreements.

That's how it should be. Sadly the EU is taking a very different approach of trying to set laws for the whole world based on very unclear (and definitely unprecedented) requirements. It's true that they will have no jurisdiction over the pizza guy - just until he comes to the EU or to an allied country. Another comment talks about how it's very likely that GDPR will be a requirement of trade deals.

Re: How GDPR Will Change The Way You Develop

#265

Is it just me or does this article manage to give advice while saying nothing at all about what is required? For example: > The first half is the General Data Protection Regulation (GDPR), which becomes enforceable across Europe on 25 May 2018. This is an overhaul, modernization, and replacement of the existing framework, the Data Protection Directive of 1995 (yes, 1995.) > All of the existing principles from the ori…

You could simply go and read the GDPR text. It's actually ok. Compared to say the Verified-by-VISA spec :)

Aye. There's a nicely formatted (non official, hosted by a consulting company) at:

https://gdpr-info.eu/

I also suggest reading a report that's helped inform the text of the GDPR:

"Privacy and Data Protection by Design":

https://www.enisa.europa.eu/publications/privacy-and-data-pr...

Re: How GDPR Will Change The Way You Develop

#266
post #252
post #214

I really don't think (and I am developer, I will need to comply) that anything in GDPR is hard to understand. Treat data from others in same way as you would treat (and you are treating) yours. You are not selling your personal details to 3rd parties, you are not keeping painfull pictures of yourself climbing to garbage bin and doing diving completely drunk, you are not storing them into pastebin or unsecured databas…

The problem is you are required to prove that you follow the rules, which would take your effort and your money. This is a "guilty until you prove you are not" thing.

> The problem is you are required to prove that you follow the rules

Yes, because the "just don't do creepy shit" approach to privacy didn't go so well. If the carrot doesn't work, the stick comes out.

Re: How GDPR Will Change The Way You Develop

#267
post #174

Will the GDPR eventually make bitcoin or other immutable public distributed databases illegal in the EU? Do you have default judgements on thousands john doe node operators around the world? Will EU ISPs be required to censor any kind of blockchain node eventually when someone has a GDPR complaint for that network? Will we arrest teenagers for running ethereum miners on their gaming computers after all of this?

Will any information that enables identification of the individual (or the other ancillary information spelled out in the article and regulations) be in the blockchain? If not, doesn't sound like it. Here is one way to think of this. Any EU citizen has a "right to be forgotten". If there is nothing in your records to identify that person, the you don't need to provide that ability.

Isn't a public key a potentially identifiable piece of info that becomes personal information if anyone (like an exchange) stores it in conjunction with other personal information? I don't see how it is any different than an IP address.

Re: How GDPR Will Change The Way You Develop

#268
post #214

I really don't think (and I am developer, I will need to comply) that anything in GDPR is hard to understand. Treat data from others in same way as you would treat (and you are treating) yours. You are not selling your personal details to 3rd parties, you are not keeping painfull pictures of yourself climbing to garbage bin and doing diving completely drunk, you are not storing them into pastebin or unsecured databas…

Software development needs some sort of Iron Ring (https://en.wikipedia.org/wiki/Iron_Ring) to remind us to be humble.

Re: How GDPR Will Change The Way You Develop

#270
post #15

Earlier quoted context omitted.

If a business decides to opt-out of doing business with the EU as a result, what measures do they need to take? Would a banner asking "Are you an EU citizen? Yes/No" suffice? Or would we have to use some kind of Geo IP tool? How would that defend against EU citizens using a VPN or Tor, and what would a business's liability be in that case?

Not all organisations will need to be compliant with GDPR. By that I mean, if your organisation only do marketing in, for example, the US and Canada, only accepts USD/CAD and they are no legitimate appearance that you do/want to do business in Europe, you are not required to be GDPR compliant, even if an european customer goes on your website and purchases a product/service. If your website accepts Euros, has multipl…

This are all limitation/qualification upon whether you qualify as providing goods/services.

Yet, that is only one of two reasons why you would be subject to GDPR, the other is "the monitoring of their behaviour as far as their behaviour takes place within the Union".

As far as I can tell, logging a european IP address together with urls (i.e. an access log like every server has) would qualify you even if you aren't doing business there.

Post reply on HN