Live data from Hacker News

Publishers Haven't Realized How Big a Deal GDPR Is

baekdal.com

121–130 of 468 posts

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#121
post #112
post #75

Earlier quoted context omitted.

IIRC it applies to EU citizens wherever they are, not just people who are on EU territory.

Article 3, "Territorial Scope": ---- begin quote ---- (1) This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not. (2) This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not e…

I liked your explanation of the three points from a few days ago [1] a lot.

[1] https://news.ycombinator.com/item?id=16752857

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#122
post #92

Earlier quoted context omitted.

Which things that are mentioned do you believe are not covered?

I’m not a GDPR lawyer or auditer, do nothing in this reply should be seen as advice. My general feel is that if he didn’t cite a specific article it was on purpose. He took implications or broad interpretations for anything not explicitly cited. A couple that jump out immediately are the requests for server locality information, retention periods & specifics about security policies are the ones that are likely to get…

That's all neatly laid out in article 13. [1]

I'm not a lawyer but having extensively studied all of GDPR recently I'm afraid the letter seems legit. If there's any error it will be a minor one.

[1] https://gdpr-info.eu/art-13-gdpr/

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#123
post #81
post #78

Earlier quoted context omitted.

> Anyone in the EU can send you such a letter, and you have 30 days to reply. What's the process for authenticating who sent the letter? Seems like a potential new attack vector.

Precisely this. Once you’ve dealt with sensitive data where authentication is required (real life, signatures with witnesses and all), the surface area for attack when it comes to data request is huge if the burden to reply is based simply on an email. Sending an email request is practically free with automation, which provides a nice way for phishers to know where targets store their information. Anyone know of how…

Im Germany you generally need to send a real letter (or a fax) and it needs to contain your signature.

"Authentication" for this is provided by harsh penalties on signature forgeries. Also, you'd only get one single data point and everything really sensitive has address data and they will* send their response to a known address.

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#124
post #89

Earlier quoted context omitted.

Is the US government GDPR compliant, or does it not do business with EU citizens? Or are they granted an expection for being trustworthy good guys unlike these unscrupulous businesses?

I would imagine that only legitimate businesses have to be GDPR compliant. Government agencies almost certainly fall under some national security exemption.

Many state run organizations have to be compliant too.

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#125
post #82

Earlier quoted context omitted.

You should note that lots of what that letter suggest it has rights to, are not rights granted under GDPR. Or at least would be subject to legal clarification. If you send that letter, expect to receive a standard response/report of data with a form response that politely & legally amounts to “piss off”. Large organizations have considerable resources set aside to make sure their “piss off” letter is legally defensib…

> That letter is likely only a problem when selectively used by a malicious actor against a small organization. Which is what is so annoying and economically destructive about regulations like these that are broadly applied to all companies, especially on the internet where single person companies are very popular. They are designed in a vindictive way against large companies like Facebook or major online retailers w…

For most smaller businesses there is no real reason to do all that much as long as you can answer such questions on an ad-hoc basis. Although of course we still have to see how widespread it will become in practice.

Basically you need to make sure you 100% know what data you collect (including any third parties) and make sure you have a good reason to collect it.

Honestly most of GDPR should be considered "common sense". It's just that many corporations actively act against the interest of individuals they collect data on, and it's precisely these practices that GDPR tries to correct.

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#126
I don't think the legislators understand the technical complexity it would take to comply with GDPR nor the benefits of tracking for the internet.

Tracking makes markets more efficient.

1. Advertisers can tune their ads/targeting to get higher conversions and sales. They pay higher PPMs and PPCs.

2. Publishers get higher PPMs and PPCs. This motivates them to invest more in their content and website because each new user will yield more money with higher PPMs.

3. Users get more relevant and safer ads. Remember the shady banner ads of the late 90's and 2000's? That's the type of low conversion rate / click through rate ads that will run when advertisers can't target their audience efficiently and PPMs are very low. Relevant ads also save users (the segment that buys stuff from ads) time from researching for products and services.

4. Users get personalized content from publishers. This has a few negatives but I would argue that it greatly improves user experience.

The technical and administrative complexity required for the legislation effectively shuts off tracking for all websites that aren't owned by a megacorp. Small and medium sized publishers now have less motivation to get good content out and improve their websites from the lower PPMs.

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#127
post #64

It's even bigger than that. It's been mentioned on HN before, but see the "GPDR Letter."[1] Anyone in the EU can send you such a letter, and you have 30 days to reply. Please confirm to me whether or not my personal data is being processed. If it is, please provide me with the categories of personal data you have about me in your files and databases. a. In particular, please tell me what you know about me in your inf…

Is there anything stopping these letters from being abused like DMCA Takedowns? Just one of these look like they'd tie up a human worker for days. How much personal information are you going to have to provide to ask for such data? Especially for ".. provide me with a copy .." Does any of this apply to "anonymized" data?

You can charge reasonable administrative fees or refuse to act if the request is "manifestly unfounded or excessive, in particular because of their repetitive character". [1]

[1] https://gdpr-info.eu/art-12-gdpr/

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#128

Earlier quoted context omitted.

Of course you can serve ads, they just can't use any personal information or tracking unless people have consented. Ad blockers will still be a thing. As for consent, you have to be able to refuse. A consent box popping up each time would be the dumbest way to do this, but not that different than those full-screen email/newsletter begging boxes we have now.

Why dumbest? If we agreed that even incognito browsing contains the traces of PII, publisher has to get my consent, explicitly, that's the whole point of GDPR. I see no other option than to do popup window for each new visitor (where new == has no associated cookie). What are other options?

Don't use the PII. Is that really too much to ask?

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#129
post #73
post #21

Earlier quoted context omitted.

I’d add: Get (documented, active) permission of users to store and use their data, understand that permission is given only for a defined cause/usage (and not indefinitely for everything you right now might not even think of), be prepared to tell users what data you store about them, why and (briefly) how it is used. Be prepared to delete user data on request. Be prepared to show documentation on how you handle the (…

Be careful with hiding everything behind "consent", because consent cannot be a precondition for providing a service. Put differently: if a user does not consent, you cannot refuse them the service if the data you wanted to collect is not strictly necessary to provide the service. The alternative is to only collect data that is strictly necessary to provide the service. In that case GDPR allows you to collect the dat…

> consent cannot be a precondition for providing a service

IANAL.

This is more nuanced than it appears, as it is balanced against the firm's right to conduct business.

If you're generating leads by providing a whitepaper, then realistically you're not going to be penalised for saying "you need to consent to receive our newsletter to access this whitepaper".

On the other hand, an airline saying "you can only book a flight on our plane by consenting to us sharing everything we know about you with loads of third parties" would be frowned upon.

Our GDPR lawyer at least has advised not to ask for consent, since it is difficult to establish whether it was given, and has not been withdrawn. It's easier to rely on legitimate business use and NOT ask for consent, as long as it genuinely falls into that category.

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#130
post #91

I’m not convinced IP addresses are automatically personal data. Granted, they CAN be personal data, if they can be linked to a specific person. But assuming I just keep generic log files, and that I would not in a subject access request be able to tell someone the IP addresses that the user has used, is it really personal data? Also, it is not clear to me what other laws require in terms of keeping log files. It is p…

GDPR defines "personal data" as "any information relating to an identified or identifiable natural person". [1]

The GDPR definition of personal data is VERY broad, and it includes things like:

* name, email, date of birth, etc (probably no surprise here)

* any user behaviour (what you look at, what you click on)

* uploaded content (what you write, your uploaded avatar etc)

* ip addresses, device ids

* beliefs, ethnicity, sexuality, health data (additional restrictions apply here)

* biometric data, genetic data (additional restrictions apply here)

[1] https://gdpr-info.eu/art-4-gdpr/

Post reply on HN