Live data from Hacker News

How GDPR Will Change The Way You Develop

smashingmagazine.com

291–300 of 710 posts

Re: How GDPR Will Change The Way You Develop

#291
post #177
post #81

Earlier quoted context omitted.

No. Professionals in engineering or the trades have to know the regulations that govern their industry and abide by them. What many SVers call "innovation", other industries would call "reckless". How embarrassing for us! EDIT: In terms of regulation, we're practically chiropractors.

The comparison is disingenuous. The internet makes anything you build automatically global. You're blasting software engineers for not knowing worldwide regulations. How many New York lawyers know the regulations of France? How many local UK construction companies know the building codes of Japan? None. Knowing all regulations in the world for any given industry would be a full time job. The people you seem to be imp…

> How many New York lawyers know the regulations of France?

New York lawyers who do business in France do.

If you're accepting ~dollars~ euros to place French ads on your pages targeting French customers, seems reasonable to know the relevant French regulations.

Re: How GDPR Will Change The Way You Develop

#292
post #178
post #157

Earlier quoted context omitted.

If your company is not targeting the EU as a market you are out of scope of GDPR. If you explicitly accept Sterling/Euros, provide localisations for EU countries, talk explicitly about your EU shipping options etc. then you would probably be seen as accommodating the EU market and might find yourself in scope.

Consider the case of an EU citizen traveling in the US transaction in USD. This person is covered. Even if they are in the US.

I really want to know where this idea is coming from. I do not see how GDPR applies here.

Re: How GDPR Will Change The Way You Develop

#293
post #273
post #261

Earlier quoted context omitted.

Can you point me to a definitive source as to what websites that have access log that include IP addresses (which is pretty much everyone) have to do to be compliant? If there are steps that must be taken, who has to taken them? I've been looking, and I have found a bunch of contradictory explanations. My best guess is that if you have a disclaimer that says you log IP addresses for security purposes, you can keep yo…

Sounds like you have a legitimate interest in logging IP addresses for security purposes, it is an effective measure and that your legitimate interest on balance outweighs the interests of the data subject. If that is the case you could probably rely on the “legal basis” called legitimate interest and do not need consent or anything like that. Do: - Make a link to a privacy policy clearly accessible (eg on your websi…

> Sounds like you have a legitimate interest in logging IP addresses for security purposes, it is an effective measure and that your legitimate interest on balance outweighs the interests of the data subject. If that is the case you could probably rely on the “legal basis” called legitimate interest and do not need consent or anything like that.

Assuming you are right, that answers part of my question. Yet, I would prefer to see this detailed by an official source.

The other part of my question still remains unanswered. The GDPR limits who qualifies as providing goods/services, but I don't see any limitation on who qualifies under "the monitoring of their behaviour as far as their behaviour takes place within the Union."

It seems like this create a legal liability for every single website with an access log unless it displays a privacy policy.

Re: How GDPR Will Change The Way You Develop

#294
post #214

I really don't think (and I am developer, I will need to comply) that anything in GDPR is hard to understand. Treat data from others in same way as you would treat (and you are treating) yours. You are not selling your personal details to 3rd parties, you are not keeping painfull pictures of yourself climbing to garbage bin and doing diving completely drunk, you are not storing them into pastebin or unsecured databas…

In principle, yes. The intention behind and the principles outlined by the GDPR are good.

However, the devil's in the details, specifically in how these principles are supposed to be implemented. Some of these details are not quite clear yet. It's almost impossible to navigate these issues without getting at least some basic legal advice and investing a fair bit of time.

Unfortunately, as often is the case with EU regulations these seem to be targeted mainly at larger companies or corporations, which can easily afford this because they have legal departments anyway.

As a company that uses third-party services for data processing (which includes almost every piece of SaaS-type software) you have to sign a data processing agreement with each of those, which can mean considerable effort.

Some suppliers unfortunately are not as well-prepared yet as they should be.

Therefore now a company's processes continuing to run smoothly might depend on some third party getting their internal affairs in order. It's true they should've done this long before and one shouldn't continue to work with them if they fail to do so. Still, it's a problem you have to deal with.

I agree that GDPR makes sense and it's a good idea to follow through with these measures. It won't be easy in each and every case though and it might be a bumpy ride at first, which is why I sincerely hope that in the beginning authorities will be lenient with parties that act in good faith.

Re: How GDPR Will Change The Way You Develop

#295
post #280

Earlier quoted context omitted.

The EU is going to send over its army and force you to comply. My understanding is the GDPR applies to residents of the EU, not just citizens, and it also applies when they are outside the EU. In practice this means it is impossible to determine if it applies unless you gather far more information than you really need from your users - “sorry we have to invade your privacy to protect your privacy”.

So a US company providing services to a US naturalized citizen in the US that is also a dual citizen of a country in the EU makes the company liable to follow these regulations? That makes no sense. This sounds unenforceable.

Yep. It is worse that it can be a EU resident (non-citizen) visiting the the USA using a USA only service and the law as currently written still applies. Good luck.

The next fun job is working out how to remove the data from all your backups when you get a removal request.

I have taken the approach that I will comply with the general intent of the GDPR (which I did long before it existed), but not try to apply the ridiculous parts.

Re: How GDPR Will Change The Way You Develop

#296

Earlier quoted context omitted.

> Lets say your visiting the USA as an EU citizen and you get a pizza delivery from a local small pizza shop If that pizza store has no relation to the EU then there is no legal ground by which the GDPR could become relevant. There is no treaty which would establish some sory of leverage here. //EDIT: which btw is unlike FATCA for which there actually are bilateral agreements.

You don't need a treaty to enforce the law, you just need a pizza shop owner who likes to vacation in europe sometimes. You carry out the default judgement if they ever arrive in the EU. The GDPR explicitly has a very global scope because it is targeting companies in and out of the EU. I wouldn't really have much of a problem with the GDPR if it had some small business and non-eu business exceptions. It doesn't and r…

It doesn't and regulators saying 'trust us we wont prosecute the easy to prosecute!' makes most businesses uneasy.

Indeed.

Let's not forget that the EU and national governments have form when it comes to this sort of thing. The new EU VAT rules on digital sales a few years back were similarly overweight, and they really did result in a lot of microbusinesses either literally shutting down or just plain breaking the law.

A lot of slightly larger ones, my own included, went to considerable lengths to update systems to comply, but with hindsight would have simply declined custom from any (other) EU nation instead because the overheads were and continue to be excessive.

Those same rules really did also result in national tax authorities abusing their new-found powers to go after businesses in other countries within the EU, sometimes through their own incompetence rather than any legitimate grievance, resulting in some very scary threats being received by other small businesses.

It's tough to give much credit to arguments about regulators exhibiting common sense and moderation when the evidence of previous sweeping EU rule changes suggests we shouldn't count on that.

Re: How GDPR Will Change The Way You Develop

#297

What's troubling to me is that it's very unclear what specifically is required. I know the linked post isn't legal advice, but in the page about 'privacy by design' linked to by the origin link, they list "Minimize the amount of collected data" as as an item (supposedly to be achieved to be in compliance with the law). What's the minimum amount of data? Who decides that? Is it dependent on context? I'd hope so! Can a…

> What's the minimum amount of data? Who decides that? Is it dependent on context? I'd hope so!

> Can any site just 'do an end run around' the law by requiring their users to agree to allow them to collect whatever data they collect now or that they've already collected? If so, that seems like it'd be likely as helpful as current terms of service.

Under the GDPR you're not allowed to store personal data.

However, if you have purpose, and need data to fulfil that purpose, you can.

You can also ask for data, in clear terms, and if an informed user, freely choose to share, you might store that.

So, you sell shoes and magazines online. You need an address to ship both. You need a shoe size to ship the right shoes. You can demand to know the shoe size before you ship shoes - but not before you ship a magazine.

You can store order information (indeed have to, due to financial regulation). So you have a record of shipped shoe size and customer data.

You may not, without consent, store a permanent profile with shoe size and magazine preference. But it's OK to let users opt in to a profile.

> Another item mentioned is "Where possible, pseudonymize personal data.". What's a practical example of that?

Good question. Off the top of my head I can't think of useful pseudonymyzation related to the GDPR.

Perhaps things like hashing IP addresses for traffic stats, or using opaque identifiers for storing session interactions rather than linking directly to IP or real names. Useful pseudonymyzation is hard.

Re: How GDPR Will Change The Way You Develop

#298
post #261

Earlier quoted context omitted.

Can you point me to a definitive source as to what websites that have access log that include IP addresses (which is pretty much everyone) have to do to be compliant? If there are steps that must be taken, who has to taken them? I've been looking, and I have found a bunch of contradictory explanations. My best guess is that if you have a disclaimer that says you log IP addresses for security purposes, you can keep yo…

Backups of various kinds are in a similar position. The reason GDPR is a bad law is that its real effect is so ambiguous. Read literally, it imposes significant burdens on data controllers, particularly because of things like the right to erasure. Those burdens may be disproportionate particularly for smaller organisations that only handle a limited amount of data in the first place. The alternative, which I've notic…

> The alternative, which I've noticed GDPR's defenders tend to favour as understanding has grown, is something to the effect that regulators won't actually enforce the rules in a draconian fashion and will only go after serious infringement in practice. But that's a dangerous position to adopt in legal matters, because ultimately it means if you go too far in complying when others don't then you are at a disadvantage, but if you don't go far enough then you are subject to being punished at any time, and there is no objective standard for how far we're talking about either way.

Exactly this. As a consumer, I really like most of the protections that GDPR provides and I want them to be widely followed and enforced.

As a freelancer who works with mostly small clients, I really wish that there was clear, official communication on what sorts of common practices need to change (or not) and examples of solutions that small businesses can implement to be compliant. Just telling them to not worry because they're too small for enforcement actions isn't a good solution since it limits privacy protection and compliance to large companies.

Re: How GDPR Will Change The Way You Develop

#299
post #225

Earlier quoted context omitted.

We will see, new regulation is coming after GDPR and I bet they will plug the missing holes there. There was a cookie law that everyone circumvented. Now the same people are complaining about GDPR. The next round is going to put even more restrictions, and the regulation is going to be blamed. But the ones to be blamed are the ones who abuse it.

I'm not sure what you mean by "holes". It seems like it's a fundamental and intended feature of the GDPR that you can't achieve compliance-by-default. You have to explicitly audit every interaction between every system you have, to ensure that either no personal information is present or the interaction complies with GDPR standards.

"...you have to explicitly audit every interaction between every system..."

But would you though? If you're a large co. you'd have a configuration management system where you just pull the specs/data rather than do an audit. If you're a small co. you'd know already, and if not you'd just go look. Right?

My experience is that anyone complaining about the amount of work GDPR is causing is a. not compliant anyway (and knows it) and/or b. has terrible or no IT governance.

Re: How GDPR Will Change The Way You Develop

#300
post #150
post #134

Suppose you were a small startup based in America, accepting online payments from users/advertisers using American platforms or financial institutions. Suppose you make no effort to comply with GPDR - what realistic consequences can you face? I suspect that this is the kind of thing which larger/established companies would worry about. If you're a seed/series-A startup, it seems like you have far more important thing…

So having been through the preliminaries of GDPR, I took away a few things. First of all, the enforcement path is as yet unclear. If they (europe) see you are doing something (like not responding to "right to be forgotten" request) it is not clear what enforcement they will attempt. Second, there is the customer perception. If you have one European customer that buys something from you, or enters their email for you…

>and they request later to be forgotten and you don't

How do you prove you have forgotten someone?

Post reply on HN