Live data from Hacker News

Publishers Haven't Realized How Big a Deal GDPR Is

baekdal.com

101–110 of 468 posts

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#101
post #73
post #21

Earlier quoted context omitted.

I’d add: Get (documented, active) permission of users to store and use their data, understand that permission is given only for a defined cause/usage (and not indefinitely for everything you right now might not even think of), be prepared to tell users what data you store about them, why and (briefly) how it is used. Be prepared to delete user data on request. Be prepared to show documentation on how you handle the (…

Be careful with hiding everything behind "consent", because consent cannot be a precondition for providing a service. Put differently: if a user does not consent, you cannot refuse them the service if the data you wanted to collect is not strictly necessary to provide the service. The alternative is to only collect data that is strictly necessary to provide the service. In that case GDPR allows you to collect the dat…

How is "strictly" defined? I'm going to guess it's define as "the magistrate knows it when it sees it", so take to be both "don't use the most egregious interpretation", and "don't be a populist punching bad that governments can make hay out of attacking".

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#102
post #20

Earlier quoted context omitted.

But there is a lot of other PID with this visit - ip address, cookies, browser fingerprint

Noob question How is that person-identitifying information? Seems like it's machine-identifying information. You can't tie it to a real-world name and email (which the top voted comment claims is the essence of GDPR).

GDPR does not concern itself only with person-identitifying information, it concerns itself with "personal data" which is defined as "any information relating to an identified or identifiable natural person". [1]

The GDPR definition of personal data is VERY broad, and it explicitly includes things like:

* name, email, date of birth, etc (probably no surprise here)

* any user behaviour (what you look at, what you click on)

* uploaded content (what you write, your uploaded avatar etc)

* ip addresses, device ids

* beliefs, ethnicity, sexuality, health data (additional restrictions apply here)

* biometric data, genetic data (additional restrictions apply here)

[1] https://gdpr-info.eu/art-4-gdpr/

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#103
post #75

Earlier quoted context omitted.

IIRC it applies to EU citizens wherever they are, not just people who are on EU territory.

So do American constitutional protections apply to Americans living in France? I am having a hard time understanding GDPR jurisdictional power. US citizens in France aren’t protected by the US Fair Credit Act with French banks, even when those French banks have US subisidiaries because a French company in France isn’t subject to US legal jurisdiction. Even FATCA doesn’t subject a French bank to US law — it subjects F…

> So do American constitutional protections apply to Americans living in France?

I'm no expert, but I thought on the whole the constitution has nothing to do with citizens -- it's a list of rules that the US government must follow. It certainly has no hold over the German government.

> This idea that EU citizens are protected worldwide is just ridiculous. EU jurisdiction doesn’t extend beyond the EU.

If you, as someone who breaks the conditions in the GDPR, have nothing to do with the EU, then you're fine.

However the GDPR applies to you, an American citizen in America who's never been to the EU, just as the DMCA applied to Dmitry Sklyarov, a Russian citizen who had never been to the U.S.

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#104
post #62

nobody realized how much big of a deal GDPR is going to be. if you digitized your partner business card, if you store their number on your phone etc that's personal data and that all need to be renegotiated and you need a database to hold track of their informed consent. a little exaggerated for fun here https://www.brandexpublishing.co.uk/the-new-procedure-for-ex...

You don't even have to digitise the information, if you were to store your business cards in a structured filing system they would be under the GDPR too [1] [1] See definition of personal data: https://ico.org.uk/for-organisations/guide-to-the-general-da...

I wonder what that means for Rolodexes.

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#105
post #3

> Today, for instance, we see that a majority of people who install an ad blocker don't actually do it to block ads (that's just an added bonus). They are actually doing it to block tracking. Is there any evidence for this at all?

I d wager adblocker usage correlates with youtube ad frequency.

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#107
post #92

Earlier quoted context omitted.

The letter is a nice mix of asks that are specifically covered, rights that might be covered & things that are not covered at all. In that sense it’s a great way to rattle someone without specific GDPR guidance. But all things being equal, the large orgs that are capable of systematic data collection, are not at all troubled by it & certainly won’t be answering it with direct point by point answers.

Which things that are mentioned do you believe are not covered?

I’m not a GDPR lawyer or auditer, do nothing in this reply should be seen as advice.

My general feel is that if he didn’t cite a specific article it was on purpose. He took implications or broad interpretations for anything not explicitly cited.

A couple that jump out immediately are the requests for server locality information, retention periods & specifics about security policies are the ones that are likely to get a very polite “we conform to industry best practices piss off” replies.

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#108
post #64

It's even bigger than that. It's been mentioned on HN before, but see the "GPDR Letter."[1] Anyone in the EU can send you such a letter, and you have 30 days to reply. Please confirm to me whether or not my personal data is being processed. If it is, please provide me with the categories of personal data you have about me in your files and databases. a. In particular, please tell me what you know about me in your inf…

Is there anything stopping these letters from being abused like DMCA Takedowns? Just one of these look like they'd tie up a human worker for days. How much personal information are you going to have to provide to ask for such data? Especially for ".. provide me with a copy .." Does any of this apply to "anonymized" data?

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#109
post #77

"If you look at what is happening around us, you can see very clear signals that the public has had enough." No, outside of a few echo chambers, no one cares about privacy or knows what GDPR is. Until GDPR shows everyday on the evening news for weeks it will not be well-known, and there are many things more important to most people than online privacy. Heck, Cambridge Analytica was only a scandal because the "bad guy…

I am yet to find one friend or family member who has changed their attitude or behaviour towards Facebook after the Cambridge Analytica.

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#110
post #91

I’m not convinced IP addresses are automatically personal data. Granted, they CAN be personal data, if they can be linked to a specific person. But assuming I just keep generic log files, and that I would not in a subject access request be able to tell someone the IP addresses that the user has used, is it really personal data? Also, it is not clear to me what other laws require in terms of keeping log files. It is p…

It doesn't matter what you consider IP addresses to be, it matters what European regulatory authorities consider them to be.

And yes, many IP addresses can be linked to a specific person. I don't doubt that, by being logged in to Google, Facebook, and a bunch of other services, and by having an ISP that provides a unique IP address per subscriber, that the majority of sites out there that use 3rd party tracking know who I am just by my IP address at any given time.

Post reply on HN