Live data from Hacker News

Publishers Haven't Realized How Big a Deal GDPR Is

baekdal.com

61–70 of 468 posts

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#61
post #38

GDPR articles seem to be getting some traction on HN as everyone is trying to figure out: "Do I need to do something for this? Is so, what?" For a recent project I read (and translated to plain english) [1] every single article in the GDPR legislation and for our purposes it can be summed up as: "Treat user data like names and emails as if they were credit card numbers" AKA: be paranoid about keeping them, encrypt th…

> some traction on HN as everyone is trying to figure out: "Do I need to do something for this? Is so, what?" If you are big enough to have to worry about this you are probably a company with plenty of resources to think and comply with this. So it's hard to imagine how many readers of HN are getting their answers on HN (or similar). If you are small time nobody is going to come after you. Sure something could happen…

If you outside the EU, it really isn’t about “anyone coming after you”. Even within the EU the enforcement actions currently err of the side of a stern warning rather than fine (except in the most deliberate cases). Though that may change.

Either way, you shouldn’t be doing it out of fear. You should be complying for practical business reason

1. This is how you should be treating personal data. 2. In exchange for complying with GDPR, you get access to a market of >700m people. If you’re a service provider, it’s illegal for any EU business to be your customer without GDPR compliance.

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#62

nobody realized how much big of a deal GDPR is going to be. if you digitized your partner business card, if you store their number on your phone etc that's personal data and that all need to be renegotiated and you need a database to hold track of their informed consent. a little exaggerated for fun here https://www.brandexpublishing.co.uk/the-new-procedure-for-ex...

You don't even have to digitise the information, if you were to store your business cards in a structured filing system they would be under the GDPR too [1]

[1] See definition of personal data: https://ico.org.uk/for-organisations/guide-to-the-general-da...

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#63

Earlier quoted context omitted.

Interesting. I personally use uBlock and "cookie autodelete", which deletes cookies for all sites except the white-listed ones each 5 minutes, automatically. So if your interpretation is correct, and GDPR affects even completely anonymous users, I'll be seeing and clicking "consent box" each time I go read a newspaper or just do general browsing. Like the "we use cookies" stuff, but on steroids. EDIT: but still, I fi…

Of course you can serve ads, they just can't use any personal information or tracking unless people have consented. Ad blockers will still be a thing. As for consent, you have to be able to refuse. A consent box popping up each time would be the dumbest way to do this, but not that different than those full-screen email/newsletter begging boxes we have now.

Why dumbest?

If we agreed that even incognito browsing contains the traces of PII, publisher has to get my consent, explicitly, that's the whole point of GDPR. I see no other option than to do popup window for each new visitor (where new == has no associated cookie). What are other options?

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#64
It's even bigger than that. It's been mentioned on HN before, but see the "GPDR Letter."[1] Anyone in the EU can send you such a letter, and you have 30 days to reply.

Please confirm to me whether or not my personal data is being processed. If it is, please provide me with the categories of personal data you have about me in your files and databases.

a. In particular, please tell me what you know about me in your information systems, whether or not contained in databases, and including e-mail, documents on your networks, or voice or other media that you may store.

b. Additionally, please advise me in which countries my personal data is stored, or accessible from....

c. Please provide me with a copy of, or access to, my personal data that you have or are processing.

2. Please provide me with a detailed accounting of the specific uses that you have made, are making, or will be making of my personal data.

3. Please provide a list of all third parties with whom you have (or may have) shared my personal data.

Then, once you've replied, they can request deletion of any or all of that.

[1] https://www.linkedin.com/pulse/nightmare-letter-subject-acce...

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#65
post #19

Still NSA and their likes do collect and store all this data, so effective privacy/data protection/anonymization is still a task of the users themselves and their client tech.

Is the US government GDPR compliant, or does it not do business with EU citizens? Or are they granted an expection for being trustworthy good guys unlike these unscrupulous businesses?

You think spies care about being compliant with privacy laws? Their job is basically not to.

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#66
post #57

Why not do it like with cookies? People are already used to accept these cookie policies, so why not just widen it to GDPR related stuff? Also how much can be caught with "security" reasons?

> Also how much can be caught with "security" reasons?

Only things you only use for security purposes. You can't say "we need X for anti-fraud" and then use it for marketing purposes without consent.

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#67
post #5

Can’t say i feel bad for them.

Why would you feel bad for them? They have had 2 years to prepare for this, hopefully a few fines here and there will make people realise this _is_ a big deal and they can't just ignore it. About time too, I really really hope this has an incredible profound impact on privacy and the EU will demonstrate this is a law people _must_ abide by.

Maybe the next version of GDPR will tighten the screws and take it all the way to the end user. You install some app and share your contacts with it? Pony up 10% of your annual income. You forgot your phone in a cab? That is putting everyone who has ever emailed you at risk. 15% of your annual income as fine for your carelessness. Would you still support it?

Such sweeping laws require a lot of thought and debate. It is unfair to say, “hey they had 2yrs so it is their problem”. We need to do better than, “must abide by law” and push for just and fair laws.

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#68
post #59
post #57

Why not do it like with cookies? People are already used to accept these cookie policies, so why not just widen it to GDPR related stuff? Also how much can be caught with "security" reasons?

There's a very clear distinction: GDPR requires that consent is not a precondition for offering a service. Most cookie policies in practice are all or nothing: you either accept and continue, or you decline and cannot use the service/website. That is not allowed under GDPR.

Interesting. Which part of GDPR disallows the “decline and you cannot use the service” case?

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#69
post #66
post #57

Why not do it like with cookies? People are already used to accept these cookie policies, so why not just widen it to GDPR related stuff? Also how much can be caught with "security" reasons?

> Also how much can be caught with "security" reasons? Only things you only use for security purposes. You can't say "we need X for anti-fraud" and then use it for marketing purposes without consent.

How can anyone check this?

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#70

Earlier quoted context omitted.

Here's #2 running a pretty similar cocktail (ublock origin, umatrix, privacy badger, httpseverywhere, cookie autodelete and decentraleyes). There's dozens of us! Dozens! But more seriously, there's actually lots of us. You don't hear about us because we don't narcissistically post about it on facebook. We just block shitty software and move on with our lives. I have no stats for you though, because stats are usually…

But the statement wasn't "many people block tracking", it's "the majority of people using ad blockers are doing it for tracking and not for ads". That's a far different statement that is far harder to back up.

So, of that list I just posted:

ad blockers: ublock origin

ad and tracking blockers: umatrix privacy badger

tracking blockers: cookie autodelete decentraleyes

other: httpseverywhere

I'm mostly blocking trackers.

Post reply on HN