Live data from Hacker News

Publishers Haven't Realized How Big a Deal GDPR Is

baekdal.com

421–430 of 468 posts

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#421

Earlier quoted context omitted.

So...use oauth?

Hurrah so now sites won't use their own logins and I'll be forced to let Google or Facebook know every site I want to connect to. That's an improvement?

OpenID Connect exists, it allows OAuth from and to unrelated services.

Neither Google nor Facebook own Oauth, they just have very incompliant implementations that force everyone to treat them as special.

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#422

Earlier quoted context omitted.

> Honestly, the best thing to do if you don’t have a high percentage of EU users/customers is to simply block EU IPs. Could you please block my IP address as well: 192.117.111.61 If you feel that being responsible with my personal information and metadata is not worth the trouble, then I don't want to accidentally ever use whatever service you maintain. Thanks.

What an absurd statement. This isn’t about being able to be “irresponsible with [your] personal data”. GDPR compliance is a difficult, expensive, onerous, and uncertain endeavor. Sites that don’t rely on EU visitors for revenue don’t need to expose themselves to the additional liability that the GDPR imposes. That doesn’t mean that sites that haven’t gone to the expensive lengths required under it are going to expose…

I'm a big enough fan of the GDPR and a big enough opponent to SESTA/FOSTA/CLOUD that I have moved almost all my business into the EU. The only remaining US business I depend on my DNS provider.

Why should I trust a US business with my personal data when I can give it to a EU business that will face harsh punishment for doing bad things with my data (the US seems to have no problem with large corporations loosing millions of user data entries as long as the big CEO says "oops, sowwy!")

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#423

Earlier quoted context omitted.

Honestly, the best thing to do if you don’t have a high percentage of EU users/customers is to simply block EU IPs. First it was the completely useless cookie notifications, now it’s GDPR, and nobody knows what the next thing will be - we only know that there will be a next thing (there always is), and that it too will be costly and burdensome to comply with. Unless you derive a significant percentage of your revenue…

> First it was the completely useless cookie notifications It was useless in the sense it was trying to play nice. It was a gentle call for the industry to self-regulate. The only problem with that law was how naïve it was. Go ahead and block the whole European IP range. See if we care.

The cookie law was also largely overblown. It only require notifications for any non-essential cookies and I think the wordpress plugins for this simply put up a blanket banner because the blog author might just be using the Google Anal ytics plugin too.

And then everyone put it up "just in case" or "because the law says all cookies". (Of course some smart people figured out that local storage is not a cookie and the law only covers cookies, atleast what they gather from hearsay instead of checking the actual text)

But tbh, I'd prefer US services IP blocking European users. It'll encourage EU startups to fill the gap and they will have the privacy regulation of the EU as marketing bullet point over any US company, eg "In the US privacy is a pinky-promise, for us privacy is law".

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#424
post #77

"If you look at what is happening around us, you can see very clear signals that the public has had enough." No, outside of a few echo chambers, no one cares about privacy or knows what GDPR is. Until GDPR shows everyday on the evening news for weeks it will not be well-known, and there are many things more important to most people than online privacy. Heck, Cambridge Analytica was only a scandal because the "bad guy…

> Until GDPR shows everyday on the evening news for weeks it will not be well-known I think we've crossed that point few months ago in Europe. Last year I felt I was probably the only one of my real-life friends who even knew what GDPR was. These days, I see streams of articles about it on social media, aimed at non-technical people. Hell, last week my SO told me she started receiving GDPR-related e-mails at work fro…

In which EU? :) Over here (Belgium), there has been a lot of talk in business fore (which are only frequented by a specific minority of companies), but in the general press I can't even recall seeing a single article. Even with those 'in the loop', the attitude is mostly 'wait an see', 'who is going to work on enforcement (the regulators haven't expanded), and 'maybe it will be another cookie-law (meaning a much hyped 'the sky is falling' regulation which turned out to be we'll install a component that handles the implicit 'ok' click and be done) and 'you never get a fine the first time, so why be proactive?'.

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#425

Earlier quoted context omitted.

If all information you have about a person is their email (and usage data) then this won’t make a difference though... The GDPR considers even an IP address personal data, even if you have no way to correlate it with a real person. So where does this leave you if you have to respond? Imagine I’m sending a request for information from a given IP address, requesting all the personal information you hold on that IP. I k…

An IP address is only personal data in combination with a timestamp or similar time-related information. I don't see an attack scenario where an attacker would gain anything useful. Note that he's propably still risking jail time over this.

German courts have ruled that IP addresses are personal data. EU courts so far agree. The timestamp is irrelevant.

The GDPR makes anything that can be potentially traced back to a person personal data, it's a much wider definition than PII.

It also means that constructing data sets may lead to personal data being generated out of non-personal data. So even if you only store IPs without timestamp, if you stored timestamps elsewhere and you could reconstruct the IP of the user, you're up for grabs.

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#426

The author claims that for one-time visitors you're not supposed to have any 3rd-party tracking code but uses Google Analytics which Ghostery counts as a tracking code. How's that going to work out for practically every site in the world?

The author is wrong. You just do what google does and ask for consent before providing access to the site. The user doesn’t need to log in to consent. Once consented, the site can set a cookie. Then that user becomes part of your “Full interaction users” bucket.

What if the user doesn't consent? As I understand it you can make no difference in your service to those that do not 'opt-in' to your tracking.

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#427

Earlier quoted context omitted.

But any of your sites should protect user data, it's the respectful thing to do. Right ? In which case would you you think it's alright for any site to not protect, say, a user home address ?

Reasonably protecting user data and complying with the GDPR are two entirely different things. There are many ways to accidentally run afoul of this law while still protecting user data.

Define "reasonably", because what I see in the wild as a freelancer is 9 times out of 10 not matching what's "reasonable" to my standards.

And what are the "many ways" you can "accidentally run afoul of this law while still protecting user data" ?

It's hard for me to grasp.

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#428
post #168
post #142

Earlier quoted context omitted.

> No, it will basically make a newsmedia site unprofitable. I think it is the EU that has not fully thought this through. Most of the news industry is already sickly, financially, and they mostly have no model other than advertising (with a very few exceptions). We have publicly funded broadcasters in most EU countries. The ad-supported news sites, on the other hand, are generally doing more harm than good. News outl…

> News outlets existed before the web, so they're not going to be threatened by breaking the ad-supported website model. If anything, the traditional newspapers will be saved by this, because if free online news disappears, people will start buying newspaper subscriptions again. We're also seeing very concerning trends in the readerships and profitability of print media (because of the Web, many think). So I don't th…

>We're also seeing very concerning trends in the readerships and profitability of print media

Why is it "very concerning" (assuming no financial interests) that a legacy form of media is struggly to dominate in terms of profitability?

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#429

Earlier quoted context omitted.

You can tie such visit to a real person. For example, if this is a Facebook user, and your site includes resources from facebook.com, Facebook will know exactly which real person visited your site, and the user did not give you consent to share such info with Facebook.

Isn't that in Facebook's court though? They acquired your name, birthdate, address, etc. And they didn't aquire it through your website. Calling IP address or screen size "person" identifying information seems a stretch to me.

No, since you are the controller of your site hosting the Facebook component. Facebook is in that workflow 'merely' a data-processor. Advertising companies have lobbied long and hard to drive an interpretation of the GDPR in which they would be considered a 'controller', resulting in 'nothing changes for the business, realy'. AFAIK, they (thankfully, from a privacy perspective) failed.

It realy is very much like environmental regulation. Before things like the EPA etc. came to be, it was a toxic 'everything goes' type of environment. Transition to a regime where businesses are held to data responsibility might be painful at first, but ultimately hugely beneficial to all.

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#430
I read this as an extended consent banner ("this site contains cookies") + user ability to hard delete pii + IP. Hard delete is substantial, but the banner is just going to be ignored like the cookie notice. If that has an affect of traffic, it'll be punishing sites that don't require login/signup, which means the average EU consumer will be required to sign up for more accounts in order to do what they did before (because if you're going to require consent, why not require signup?). In any case, I can't see very many use cases where a site dials back its data collecting. Retargeting is the crux of ad-supported sites.
Post reply on HN