Live data from Hacker News

Publishers Haven't Realized How Big a Deal GDPR Is

baekdal.com

461–468 of 468 posts

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#461

Earlier quoted context omitted.

Right, the line does get rather blurry when a service provider has the power to compel people to purchase their "service" whether they want to or not. Local governments like to position such payments as "fees"—it makes for better PR—but if there are penalties for opting out (such as not being permitted to occupy your own property) then I would consider it a tax. In the cases you mentioned, for example, there really i…

There is a substantial difference between fees and taxes. Fees are tied to something specific. This has two implications: First, they cannot be used for something else. Second: The height of the fee must not exceed the cost of the service and thus is at least in principle something that can be checked. For example, some public health insurance providers in germany had excess money and they had to refund that to their…

> Fees are tied to something specific. ... they cannot be used for something else. ... The height of the fee must not exceed the cost of the service....

In Germany that may be true, but I was speaking of the US, where the terms are used differently. There is no expectation here that "fees" can only be used to defray the cost of providing specific services.

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#462
post #38

Earlier quoted context omitted.

> some traction on HN as everyone is trying to figure out: "Do I need to do something for this? Is so, what?" If you are big enough to have to worry about this you are probably a company with plenty of resources to think and comply with this. So it's hard to imagine how many readers of HN are getting their answers on HN (or similar). If you are small time nobody is going to come after you. Sure something could happen…

If you outside the EU, it really isn’t about “anyone coming after you”. Even within the EU the enforcement actions currently err of the side of a stern warning rather than fine (except in the most deliberate cases). Though that may change. Either way, you shouldn’t be doing it out of fear. You should be complying for practical business reason 1. This is how you should be treating personal data. 2. In exchange for com…

I wonder if a significant amount of small businesses/startups are going to simply not do business with the EU because of GDPR. I know I'd probably rather not have to deal with it if I had a small app or something.

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#463

Earlier quoted context omitted.

Reasonably protecting user data and complying with the GDPR are two entirely different things. There are many ways to accidentally run afoul of this law while still protecting user data.

Define "reasonably", because what I see in the wild as a freelancer is 9 times out of 10 not matching what's "reasonable" to my standards. And what are the "many ways" you can "accidentally run afoul of this law while still protecting user data" ? It's hard for me to grasp.

(I'm not the one you replied to.)

I'd like to see a complete and concise list of exactly what needs to be done to comply with GDPR. Everything I've seen so far has been vague legalese open to subjective interpretation. Pretty scary when the punishment for an incorrect interpretation is a 20M EUR fine.

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#464

Earlier quoted context omitted.

This is my main question actually. While most of GDPR is common sense and shouldn't be much of a burden on companies[1], I was always confused about jurisdiction. While most larger companies have a legal presence somewhere within the EU that can be held accountable for this, I do wonder how the EU is supposed to be enforce penalties on a company outside of the EU. [1]: well, the difficulty grows the larger your compa…

> I do wonder how the EU is supposed to be enforce penalties on a company outside of the EU Realistically, they can't and won't unless it's a very large scale that's worth pursuing, for a multi-national corporation with enough money to pay a big fine. If a company is not doing business in the EU, not selling into the EU, they can of course entirely ignore the GDPR. In the case of a large company that sells into the E…

It depends. When Canada's anti-spam law was introduced in 2014, the intent was to allow a private right of action effective July 1, 2017. This would theoretically mean US/foreign companies could be dragged into class-action lawsuits in Canada. This private right of action was delayed and is currently under review, but nevertheless anyone marketing to Canadians is subject to CASL laws, regardless of where their business is located. We'll see what happens, but if/when the private right of action is implemented it could potentially be a big deal.

IANAL but I can imagine a similar situation happening with GDPR.

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#465

GDPR articles seem to be getting some traction on HN as everyone is trying to figure out: "Do I need to do something for this? Is so, what?" For a recent project I read (and translated to plain english) [1] every single article in the GDPR legislation and for our purposes it can be summed up as: "Treat user data like names and emails as if they were credit card numbers" AKA: be paranoid about keeping them, encrypt th…

Honestly, the best thing to do if you don’t have a high percentage of EU users/customers is to simply block EU IPs. First it was the completely useless cookie notifications, now it’s GDPR, and nobody knows what the next thing will be - we only know that there will be a next thing (there always is), and that it too will be costly and burdensome to comply with. Unless you derive a significant percentage of your revenue…

Better yet, comply and get your privacy/data management chops together so that you're comfortably able to navigate a world where this type of legislation is likely to become more and more common. Not to mention the fact that there's an increase in interest/awareness about these matters amongst the general public.

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#466

GDPR articles seem to be getting some traction on HN as everyone is trying to figure out: "Do I need to do something for this? Is so, what?" For a recent project I read (and translated to plain english) [1] every single article in the GDPR legislation and for our purposes it can be summed up as: "Treat user data like names and emails as if they were credit card numbers" AKA: be paranoid about keeping them, encrypt th…

That's a fair analogy! I do think having a service like stripe for pii would make things easier. Why would we need first name and email address? As programmer I only need user ID!

I don't think this would be sufficient in many cases. If you store any form of user-generated content, or even a recommendation model generated from a user's past behavior, I'm pretty sure that's also considered personally identifiable information under GDPR, and since it's part of your product, you can't just outsource handling of it. It gets even stickier if that data is intertwined with data from other users, as could be the case in machine learning models or used-generated collaborative projects.

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#467

Earlier quoted context omitted.

One of our mobile apps, Firefox Focus, pointedly targets users who want to block tracking but don’t care about advertising otherwise. I’ve personally heard a pair of unprompted non-tech people in a non-tech city discussing it over beer after work. I submit the existence of our app and my personal experience as sufficient to meet the terms of your question. “is there any evidence at all”: yes!

your anecdote - not evidence - supports a claim that some people care about blocking trackers more than blocking ads. Which is a lot less contentious a claim than " a majority of people who install an ad blocker don't actually do it to block ads"

Indeed. If you’re truly in need of proof of the original claim, search advertising industry news for their various survey results of real people. The ad industry is pretty convinced that people are generally anti-trackers and not as much anti-ads. (They could be wrong, as could their surveys — but if you trust nothing, then no point can be proven.)

Re: Publishers Haven't Realized How Big a Deal GDPR Is

#468
post #299

Earlier quoted context omitted.

I love this comment. Waiting for people to take the bait and reply to you!

Take the bait? I’m not saying anything controversial. A large percentage of websites are directed at the home country of their owners anyway, and EU traffic is often incidental and worthless to them. A US dentist or doctor likely has no interest in receiving appointments from people in the EU, for example. An online store based in the US, who would have to charge outlandish shipping rates to ship to the EU, is unlike…

You don't think it's controversial to tell business to block the other half of the civilized world?
Post reply on HN