It's even bigger than that. It's been mentioned on HN before, but see the "GPDR Letter."[1] Anyone in the EU can send you such a letter, and you have 30 days to reply. Please confirm to me whether or not my personal data is being processed. If it is, please provide me with the categories of personal data you have about me in your files and databases. a. In particular, please tell me what you know about me in your inf…
> Anyone in the EU can send you such a letter, and you have 30 days to reply. What's the process for authenticating who sent the letter? Seems like a potential new attack vector.
Publishers Haven't Realized How Big a Deal GDPR Is
81–90 of 468 posts
Re: Publishers Haven't Realized How Big a Deal GDPR Is
#82It's even bigger than that. It's been mentioned on HN before, but see the "GPDR Letter."[1] Anyone in the EU can send you such a letter, and you have 30 days to reply. Please confirm to me whether or not my personal data is being processed. If it is, please provide me with the categories of personal data you have about me in your files and databases. a. In particular, please tell me what you know about me in your inf…
You should note that lots of what that letter suggest it has rights to, are not rights granted under GDPR. Or at least would be subject to legal clarification. If you send that letter, expect to receive a standard response/report of data with a form response that politely & legally amounts to “piss off”. Large organizations have considerable resources set aside to make sure their “piss off” letter is legally defensib…
Which is what is so annoying and economically destructive about regulations like these that are broadly applied to all companies, especially on the internet where single person companies are very popular. They are designed in a vindictive way against large companies like Facebook or major online retailers who burned customera due to minimal information security investment.
But they so often ignore the reality of the burden it places on small firms who account for 90% of businesses and 50% of employment, who cant afford lawyers or the legal risks of a 'piss off' letter.
The western economic environment countinually gets more and more structured favouring large firms, encouraging large scale merging, which usually generates the type of large oligopoly companies who most often does the things that cause regulations to get created, then imposed on smaller firms.
If Japan's economy is any indication we do not want to state heavy economy where big companies are the only sanctioned winners and smaller companies are heavily disincentived by the state (whether indirectly, by side effect, or overtly).
If not having these laws created isnt an option (seemingly impossible in an administrative heavy org like EU), I then hope someday these regulation start being structures like progressive income tax using size minimums or are contained to specific industries where it's clearly a problem (both of which would apply well to minimum wage laws for example). So laws are pinned directly to a specific problem area justifying the heavy-handed state intervention, not just blanket laws on everyone.
Re: Publishers Haven't Realized How Big a Deal GDPR Is
#83Re: Publishers Haven't Realized How Big a Deal GDPR Is
#84Earlier quoted context omitted.
> some traction on HN as everyone is trying to figure out: "Do I need to do something for this? Is so, what?" If you are big enough to have to worry about this you are probably a company with plenty of resources to think and comply with this. So it's hard to imagine how many readers of HN are getting their answers on HN (or similar). If you are small time nobody is going to come after you. Sure something could happen…
>If you are big enough to have to worry about this you are probably a company with plenty of resources to think and comply with this You'd be surprised. GDPR is vague enough and just open to interpretation enough that there are many different companies interpreting it in many different ways. I'm a consultant and I talk to many multi-nationals and all of them have their own spin on it. Especially around the "except wh…
Re: Publishers Haven't Realized How Big a Deal GDPR Is
#85Earlier quoted context omitted.
If I have an IRC service that shows quotes from people and has 'last seen' functionality is that covered by GDPR? Some of the users are from EU countries, does that mean those features need to be turned off or have some sort of acceptance exchange with users? Would filtering out EU IP ranges be sufficient, or does this also apply to EU citizens traveling outside of the EU? The referenced page says that asking users t…
IIRC it applies to EU citizens wherever they are, not just people who are on EU territory.
Are Dutch citizens in Oklahoma protected by Dutch narcotics laws? Of course not. They are subject to the jurisdiction in which they are physically present.
However, a US citizen can be subject to US laws overseas, however, that’s between the American and the US government — the intermediary country has no involvement unless it’s an extradition request.
This idea that EU citizens are protected worldwide is just ridiculous. EU jurisdiction doesn’t extend beyond the EU. The idea that GDPR requests have to be honored by some local ecommerce company in Idaho is just nonsense and not supported by any international legal precedent.
Re: Publishers Haven't Realized How Big a Deal GDPR Is
#86Earlier quoted context omitted.
> Also how much can be caught with "security" reasons? Only things you only use for security purposes. You can't say "we need X for anti-fraud" and then use it for marketing purposes without consent.
How can anyone check this?
Part of GDPR effect is that if you get caught, you can't talk it away with some blanket claim in your EULA, you need to have a detailed justification, and there is potential for painful fines, so the risk increases.
Re: Publishers Haven't Realized How Big a Deal GDPR Is
#87Earlier quoted context omitted.
If I have an IRC service that shows quotes from people and has 'last seen' functionality is that covered by GDPR? Some of the users are from EU countries, does that mean those features need to be turned off or have some sort of acceptance exchange with users? Would filtering out EU IP ranges be sufficient, or does this also apply to EU citizens traveling outside of the EU? The referenced page says that asking users t…
IIRC it applies to EU citizens wherever they are, not just people who are on EU territory.
Re: Publishers Haven't Realized How Big a Deal GDPR Is
#88Earlier quoted context omitted.
You should note that lots of what that letter suggest it has rights to, are not rights granted under GDPR. Or at least would be subject to legal clarification. If you send that letter, expect to receive a standard response/report of data with a form response that politely & legally amounts to “piss off”. Large organizations have considerable resources set aside to make sure their “piss off” letter is legally defensib…
Not true; GDPR explicitly grants a large number of rights to the data subject. [1] These rights include: * the right to be informed about what data is processed * the right to access all data gathered about them * the right to rectification of incorrect data * the right to receive an export of the data in a common format * the right to object, to have all data removed, and to restrict processing until further notice…
In that sense it’s a great way to rattle someone without specific GDPR guidance. But all things being equal, the large orgs that are capable of systematic data collection, are not at all troubled by it & certainly won’t be answering it with direct point by point answers.
Re: Publishers Haven't Realized How Big a Deal GDPR Is
#89Still NSA and their likes do collect and store all this data, so effective privacy/data protection/anonymization is still a task of the users themselves and their client tech.
Is the US government GDPR compliant, or does it not do business with EU citizens? Or are they granted an expection for being trustworthy good guys unlike these unscrupulous businesses?
Re: Publishers Haven't Realized How Big a Deal GDPR Is
#90Earlier quoted context omitted.
IIRC it applies to EU citizens wherever they are, not just people who are on EU territory.
So do American constitutional protections apply to Americans living in France? I am having a hard time understanding GDPR jurisdictional power. US citizens in France aren’t protected by the US Fair Credit Act with French banks, even when those French banks have US subisidiaries because a French company in France isn’t subject to US legal jurisdiction. Even FATCA doesn’t subject a French bank to US law — it subjects F…
This is true. GDPR would only apply there if they were "offering goods or services, irrespective of whether a payment of the data subject is required, to data subjects in the European Union". [1]
This is understood to mean they must be marketing to the EU, for example by offering their site in European languages (apart from English), using European currencies, or using a European domain.