Live data from Hacker News

Publishers Haven't Realized How Big a Deal GDPR Is

baekdal.com

91–100 of 468 posts

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#91
I’m not convinced IP addresses are automatically personal data. Granted, they CAN be personal data, if they can be linked to a specific person. But assuming I just keep generic log files, and that I would not in a subject access request be able to tell someone the IP addresses that the user has used, is it really personal data? Also, it is not clear to me what other laws require in terms of keeping log files. It is possible that by keeping no log files at all, you risk breaking some other law (UK).

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#92
post #80

Earlier quoted context omitted.

Not true; GDPR explicitly grants a large number of rights to the data subject. [1] These rights include: * the right to be informed about what data is processed * the right to access all data gathered about them * the right to rectification of incorrect data * the right to receive an export of the data in a common format * the right to object, to have all data removed, and to restrict processing until further notice…

The letter is a nice mix of asks that are specifically covered, rights that might be covered & things that are not covered at all. In that sense it’s a great way to rattle someone without specific GDPR guidance. But all things being equal, the large orgs that are capable of systematic data collection, are not at all troubled by it & certainly won’t be answering it with direct point by point answers.

Which things that are mentioned do you believe are not covered?

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#93
post #7

What if I told you... (Morpheus photo) 1. Social websites don’t have to be giant, centralized communities too big to police themselves. 2. People need more tools to help them achieve things in the real world, rather than spending hours a day chatting about the real world online. 3. There are ways to make money online without ads begging you to click on them, and they involve real-world goods and services that your we…

>There are ways to make money online without ads begging you to click on them, and they involve real-world goods and services that your website can help connect people for? Not every website is in a position to sell something directly. That's how ads work in the first place. I run a collaborative writing forum that is predominantly used by teens. I make so little money off it that I'm running it as a charity because…

The question is whether your ads really need to be targeted to individual persons (requiring a huge surveillance infrastructure) or if you can just sell ads to some sponsors and everybody sees the same ads.

I prefer the second option. Nothing wrong with ads per se.

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#94
post #75

Earlier quoted context omitted.

IIRC it applies to EU citizens wherever they are, not just people who are on EU territory.

So do American constitutional protections apply to Americans living in France? I am having a hard time understanding GDPR jurisdictional power. US citizens in France aren’t protected by the US Fair Credit Act with French banks, even when those French banks have US subisidiaries because a French company in France isn’t subject to US legal jurisdiction. Even FATCA doesn’t subject a French bank to US law — it subjects F…

This is my main question actually.

While most of GDPR is common sense and shouldn't be much of a burden on companies[1], I was always confused about jurisdiction. While most larger companies have a legal presence somewhere within the EU that can be held accountable for this, I do wonder how the EU is supposed to be enforce penalties on a company outside of the EU.

[1]: well, the difficulty grows the larger your company/product is, but chances are you have more resources available to dedicate to it anyway

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#95
post #38

Earlier quoted context omitted.

> some traction on HN as everyone is trying to figure out: "Do I need to do something for this? Is so, what?" If you are big enough to have to worry about this you are probably a company with plenty of resources to think and comply with this. So it's hard to imagine how many readers of HN are getting their answers on HN (or similar). If you are small time nobody is going to come after you. Sure something could happen…

In general I agree with your assessment, that being said I do think that the GDPR is a decent set of guidelines for putting in place a system that respects user data in a way that clearly has not been happening.

Why not prevent personal data from leaking in first place? It's a solution applied at the wrong level, a or wrongly drawn system boundary if you will. The damage it causes is psychological, preventing many EU businesses from starting in first place. They're destroying the food chain for startups (small independent businesses).

The EU and politcians are anti UX, they have no clue about the effect of their laws on people.

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#96

GDPR articles seem to be getting some traction on HN as everyone is trying to figure out: "Do I need to do something for this? Is so, what?" For a recent project I read (and translated to plain english) [1] every single article in the GDPR legislation and for our purposes it can be summed up as: "Treat user data like names and emails as if they were credit card numbers" AKA: be paranoid about keeping them, encrypt th…

> For a recent project, I read

Fixed that for you.

Usually commas aren't important, but that specific sentence really suffers in readability without it.

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#97
post #69
post #66

Earlier quoted context omitted.

> Also how much can be caught with "security" reasons? Only things you only use for security purposes. You can't say "we need X for anti-fraud" and then use it for marketing purposes without consent.

How can anyone check this?

We cannot say for sure yet, but in general we can expect that these things will never be checked until there is a data breach of some kind; or if evidence is found in another way.

If the details of the breach indicate you were using data for another purpose than what was allowed you will have a problem.

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#98
post #73
post #21

Earlier quoted context omitted.

I’d add: Get (documented, active) permission of users to store and use their data, understand that permission is given only for a defined cause/usage (and not indefinitely for everything you right now might not even think of), be prepared to tell users what data you store about them, why and (briefly) how it is used. Be prepared to delete user data on request. Be prepared to show documentation on how you handle the (…

Be careful with hiding everything behind "consent", because consent cannot be a precondition for providing a service. Put differently: if a user does not consent, you cannot refuse them the service if the data you wanted to collect is not strictly necessary to provide the service. The alternative is to only collect data that is strictly necessary to provide the service. In that case GDPR allows you to collect the dat…

It raises interesting question. What if some publisher, say, newspaper, can show highly targeted ads for $3 CPM, or generic ads for $1 CPM.

Can such publisher claim that collecting data is strictly necessary to provide the service? With threefold difference in ad revenue, that could be actually the case.

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#99
post #5

Earlier quoted context omitted.

Why would you feel bad for them? They have had 2 years to prepare for this, hopefully a few fines here and there will make people realise this _is_ a big deal and they can't just ignore it. About time too, I really really hope this has an incredible profound impact on privacy and the EU will demonstrate this is a law people _must_ abide by.

Maybe the next version of GDPR will tighten the screws and take it all the way to the end user. You install some app and share your contacts with it? Pony up 10% of your annual income. You forgot your phone in a cab? That is putting everyone who has ever emailed you at risk. 15% of your annual income as fine for your carelessness. Would you still support it? Such sweeping laws require a lot of thought and debate. It…

What makes you think this hasn’t had a lot of thought and debate? https://edps.europa.eu/data-protection/data-protection/legis... shows it took from June 2011 to December 2015 (at least; it builds on the European Data Protection Directive, whose history goes back to 1980 (https://en.m.wikipedia.org/wiki/Data_Protection_Directive#Co...) to create.

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#100
post #3

> Today, for instance, we see that a majority of people who install an ad blocker don't actually do it to block ads (that's just an added bonus). They are actually doing it to block tracking. Is there any evidence for this at all?

Personally I do it for both, but I also run pretty locked down on my daily driver Firefox (less so on Chrome, which I use for sites that Just Won't Run without a bunch of dependencies that I don't want to individually whitelist).

For users I deal with, I do it as a preventive measure - I worry about phishing/spearphishing and other email vectored attacks, compromised websites, and the risk of a compromised ad network where even if something malicious is killed in minutes it could still reach tens of thousands of people.

And I still get AV alerts at least a couple times a month where the AV has blocked access to something that's recognizably part of a remote access scam.

Post reply on HN