Live data from Hacker News

How GDPR Will Change The Way You Develop

smashingmagazine.com

331–340 of 710 posts

Re: How GDPR Will Change The Way You Develop

#331
post #150

Earlier quoted context omitted.

So having been through the preliminaries of GDPR, I took away a few things. First of all, the enforcement path is as yet unclear. If they (europe) see you are doing something (like not responding to "right to be forgotten" request) it is not clear what enforcement they will attempt. Second, there is the customer perception. If you have one European customer that buys something from you, or enters their email for you…

>and they request later to be forgotten and you don't How do you prove you have forgotten someone?

You attest so legally binding. The legal system does not function on mathematical proofs. If it turns out you did not speak the truth, you can be fined, and maybe even jailed. That's how it works.

Also, we are not talking about forgetting someone personally, but deleting their data. I assume that's clear.

Re: How GDPR Will Change The Way You Develop

#332
post #214

I really don't think (and I am developer, I will need to comply) that anything in GDPR is hard to understand. Treat data from others in same way as you would treat (and you are treating) yours. You are not selling your personal details to 3rd parties, you are not keeping painfull pictures of yourself climbing to garbage bin and doing diving completely drunk, you are not storing them into pastebin or unsecured databas…

If only it was that easy. A reasonable reading of GDPR makes standard web server logs (which contain IP addresses) a punishable offense, even if you don’t have a nexus in Europe.

GDPR is a wonderful idea that will be insanely expensive to comply with, act as a continuous drag on developing new technologies, and end up offering only nominal protection to end users. This is just going to be another way for EU regulators to smack around Google and Facebook. They probably deserve it, but the potential fallout for the rest of us is really going to hurt.

Don’t get me wrong, treating user data with respect is the right thing to do. But we’re all going to be paying for this overly broad and under specified legislation for years to come.

Re: How GDPR Will Change The Way You Develop

#333

Earlier quoted context omitted.

Based on a pretty thorough bit of search I can confidently say that no small (or even mid sized) US company has ever been fined or any executives detained or extradited because of breaking an EU law that would have not normally resulted in a criminal conviction. The EU tends to go after the larger entities and tends to fine rather than arrest.

The history of laws suggest that to rely on non-enforcement of a law is not wise. The GDPR is a good idea that has been written badly.

I've read most of it and I disagree that it has been written badly. As laws come it is accessible, has some pretty clearly defined goals and it is for the most part something you could easily comply with.

Re: How GDPR Will Change The Way You Develop

#334

Earlier quoted context omitted.

The problem is that the law applies to them even if they use a proxy. If they report/sue you afterwards, you might be looking at a huge amount of trouble.

People will just add a checkbox that the customer must check to complete the transaction: [] I affirm that I an not an EU citizen.

That's not possible according to GDPR.

Edit: downvotes? Really? Did you guys read the law at all?

Re: How GDPR Will Change The Way You Develop

#335
post #207

Earlier quoted context omitted.

And remember that GDPR applies to EU citizens outside the EU too, so you’d need to confirm with the user upfront that they aren’t an EU citizen before capturing the information.

I don't think it does. "This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union..." (Ch 1, art 3, para 2)

Hmm, thanks for that. Will need to read this more closely.

Re: How GDPR Will Change The Way You Develop

#336

Earlier quoted context omitted.

The GDPR is not an extra-territorial law. It merely concerns itself with EU citizens.

If the law applies outside the EU (for instance, if EU citizens travel to a non-EU country), then it is an extra-territorial law. As far as I understand the discussion here (which may or may not correspond with the actual law), the GDPR goes with the person. Wherever an EU citize goes, that EU citizen must be able to be forgotten, despite if the location they are in is outside EU jurisdiction. That is practically the…

EU citizens outside of the EU are out of scope for the GDPR.

Re: How GDPR Will Change The Way You Develop

#337
post #268

Earlier quoted context omitted.

Software development needs some sort of Iron Ring ( https://en.wikipedia.org/wiki/Iron_Ring ) to remind us to be humble.

As you can see in the article, it already exists in Canada. Some engineering schools like École de technologie supérieure (ÉTS) offers a 4 year Software Engineering program that enable you to become a member of the Ordre des ingénieurs du Québec. It's a self-regulatory body that governs Quebec's professional engineers. There is a ceremony where they give you an iron ring, mostly to remind you to be humble and to alwa…

Yes, but there's little point to it. There's a secondary exam, and unless you're going into a field involving safety-critical applications, they don't need P.E.s.

Re: How GDPR Will Change The Way You Develop

#338

Earlier quoted context omitted.

Isn't this, like, the cornerstone of bad reasoning; acting/enforcing on a few one-offs?

What do you mean one-offs? Pretty much every company with an engineer on staff is collecting as much data as they can with zero regard to the user's expectations of privacy. The regulation exists to stop an epidemic, not to act on a few one-offs.

If the user wanted privacy, they wouldn't be giving data to our services. It's a bit ridiculous to punish us for keeping what users freely give us.

Re: How GDPR Will Change The Way You Develop

#339

Earlier quoted context omitted.

> in which case what is the risk of keeping them around anyway? GDPR wants you to think differently about it: if you want to keep data, ensure that you actually need it. Do not treat data as an asset but as a liability.

We've been careful about what data we collect since day one, long before the GDPR was an issue. We're not doing anything shady with the data we do have, and we actively avoid questionable practices particularly around marketing, where we have ethical problems with being intrusive or compromising people's privacy regardless of any legal constraints. And yet having read the GDPR and much commentary about it, we're stil…

> We're not doing anything shady with the data we do have

But you can never guarantee that someone else won't do. The biggest issue to user's privacy has traditionally been data breaches. So even if you don't want to do something shady, a data loss might still be highly problematic for users.

I agree that IP addresses are unlikely to be the biggest concern here however.

Re: How GDPR Will Change The Way You Develop

#340
post #214

I really don't think (and I am developer, I will need to comply) that anything in GDPR is hard to understand. Treat data from others in same way as you would treat (and you are treating) yours. You are not selling your personal details to 3rd parties, you are not keeping painfull pictures of yourself climbing to garbage bin and doing diving completely drunk, you are not storing them into pastebin or unsecured databas…

> Every complaint about it shows that you don't respect others and you dont care about them. And this is the reason it became legislation.

Ok, that is just silly. This sounds so much like the 'Why do you want privacy if you have nothing to hide?' arguments. It is very reasonable to both have a company that handle customer data responsibly AND have issues with the GDPR.

Imagine if every time you walked down the street, the police stopped you and made you prove that you hadn't murdered anyone that day. You might get get annoyed at the 10 minutes it takes to prove our innocence. If you complained about the extra time and intrusion, would a fair response be "Every complaint about this check shows you don't care about murder"

No, you can both agree with a goal of a regulation and disagree with the mechanism that they implement it. It is certainly NOT the case that 'the only thing GDPR wants from you is to handle others data with the same RESPECT as you handle yours'... they want you to DEMONSTRATE this in a particular manner. Those particulars are important, and we can disagree on them without it being some sort of moral conflict.

Post reply on HN