Live data from Hacker News

2018 reform of EU data protection rules

ec.europa.eu

11–20 of 150 posts

Re: 2018 reform of EU data protection rules

#11
post #2

An important one to note as it's applicable to all businesses whose customers include EU residents because it addresses the collection and processing of their personal data locally and internationally.

I honestly can't wait to ask my local retailer what data they have on me based on their loyalty cards. So far they were exempt from data disclosure laws because they were not an IT company.

I always lose my loyalty card from time to time (it doesn't have any loyalty advantages you just have to have it to get the discounts) and ask for a new one. I wonder if they were able to link them back together

Re: 2018 reform of EU data protection rules

#12
This guide does not clarify one important question: Does a company in the EU have to apply gdpr guidelines for none European users. If so, this would be a significant disadvantage for all European companies since their none European competitors obviously only have to comply for European users.

One scenario in which this would be very relevant: A website needs to show a very long consent form to users that want to use their service, under gdpr regulation. Under gdpr these consent forms are very alarming and they will have a drop-off rate. The drop-off rate of the form will be the competitive advantage of none European companies.

Hence, will we see an exodus of European startups from Europe to the US?

Re: 2018 reform of EU data protection rules

#14
Enforcement factsheet: https://ec.europa.eu/commission/sites/beta-political/files/d...

Pretty clearly primarily enforced by national regulatory agencies, who are the only ones who can apply fines.

It mentions citizens taking companies to court, but https://ec.europa.eu/commission/sites/beta-political/files/d... says that's for monetary damages, not for fines. This is unchanged from previous laws.

Can people stop freaking out now?

Re: 2018 reform of EU data protection rules

#15
post #10
post #2

An important one to note as it's applicable to all businesses whose customers include EU residents because it addresses the collection and processing of their personal data locally and internationally.

I do not believe that is correct. Right now, for example, if you are a US business with no offices or employees in EU jurisdiction then there is little the EU can do if you are not GDPR compliant - regardless of whether you deal with EU traffic or not. The EU might wish their laws were global, but that doesn’t make it so. #notalawyer

You're not wrong, but, what internet company doesn't operate within the EU? If you operate in the EU, and handle EU citizen's data, you have to conform to the GDPR.

I don't think there's many internet companies that would not serve the EU because of it. Although, Google did pull out of China due to the censorship demands and the like.

Re: 2018 reform of EU data protection rules

#17
post #11

Earlier quoted context omitted.

I honestly can't wait to ask my local retailer what data they have on me based on their loyalty cards. So far they were exempt from data disclosure laws because they were not an IT company.

I always lose my loyalty card from time to time (it doesn't have any loyalty advantages you just have to have it to get the discounts) and ask for a new one. I wonder if they were able to link them back together

I always switch my loyalty cards with random people I meet on the subway, etc.

Re: 2018 reform of EU data protection rules

#18
post #5

Earlier quoted context omitted.

I honestly can't wait to ask my local retailer what data they have on me based on their loyalty cards. So far they were exempt from data disclosure laws because they were not an IT company.

Ooh, I never thought of that, but now I am very very excited about it myself.

But the answer you get might be less exciting. They might say: "We know you bought A, B, and C".

What if they give you only part of what they know? How would you be able to tell if they know more? And even if you could, how would you convince authorities that something is wrong?

Re: 2018 reform of EU data protection rules

#19

Nice guidelines, seems like for most small businesses it will be straight forward to be GDPR compliant

you are vastly underestimating the ease of implementation

Depends on your business. I didn't find it as hard as PCI compliance for instance

Re: 2018 reform of EU data protection rules

#20

Earlier quoted context omitted.

I honestly can't wait to ask my local retailer what data they have on me based on their loyalty cards. So far they were exempt from data disclosure laws because they were not an IT company.

If you are in the UK, you can already ask for the information under the DPA.

But they could charge you a reasonable fee before. Now it will be free!
Post reply on HN