Live data from Hacker News

2018 reform of EU data protection rules

ec.europa.eu

21–30 of 150 posts

Re: 2018 reform of EU data protection rules

#22

Enforcement factsheet: https://ec.europa.eu/commission/sites/beta-political/files/d... Pretty clearly primarily enforced by national regulatory agencies, who are the only ones who can apply fines . It mentions citizens taking companies to court, but https://ec.europa.eu/commission/sites/beta-political/files/d... says that's for monetary damages, not for fines. This is unchanged from previous laws. Can people stop fre…

In Germany offenses against the GDPR can cause a "Abmahnung" which do not result in a fine but a charge. There a legions of filthy lawyers waiting for the 25.5.

Re: 2018 reform of EU data protection rules

#23
post #11

Earlier quoted context omitted.

I honestly can't wait to ask my local retailer what data they have on me based on their loyalty cards. So far they were exempt from data disclosure laws because they were not an IT company.

I always lose my loyalty card from time to time (it doesn't have any loyalty advantages you just have to have it to get the discounts) and ask for a new one. I wonder if they were able to link them back together

Unless you always pay cash - it should be trivial to link by the payment card number.

Re: 2018 reform of EU data protection rules

#24
post #18
post #5

Earlier quoted context omitted.

Ooh, I never thought of that, but now I am very very excited about it myself.

But the answer you get might be less exciting. They might say: "We know you bought A, B, and C". What if they give you only part of what they know? How would you be able to tell if they know more? And even if you could, how would you convince authorities that something is wrong?

Also, they may have data that they just didn't "mine" yet. This may be data that they simply can't give you because it may concern you AND other people.

Re: 2018 reform of EU data protection rules

#25
post #10

Earlier quoted context omitted.

I do not believe that is correct. Right now, for example, if you are a US business with no offices or employees in EU jurisdiction then there is little the EU can do if you are not GDPR compliant - regardless of whether you deal with EU traffic or not. The EU might wish their laws were global, but that doesn’t make it so. #notalawyer

You're not wrong, but, what internet company doesn't operate within the EU? If you operate in the EU, and handle EU citizen's data, you have to conform to the GDPR. I don't think there's many internet companies that would not serve the EU because of it. Although, Google did pull out of China due to the censorship demands and the like.

If you have users in the EU, but no actual physical or legal presence whatsoever within the EU, technically you "have to" comply. But if you do not do so, there will not be any consequences.

As such, effectively it is not in scope and does not need to be considered.

However there are cases where you might still run into trouble. For example, if you accept payments from people in the EU, you may well end up being forced to comply via the payment networks' presence in the EU.

Re: 2018 reform of EU data protection rules

#26

This guide does not clarify one important question: Does a company in the EU have to apply gdpr guidelines for none European users. If so, this would be a significant disadvantage for all European companies since their none European competitors obviously only have to comply for European users. One scenario in which this would be very relevant: A website needs to show a very long consent form to users that want to use…

> This guide does not clarify one important question: Does a company in the EU have to apply gdpr guidelines for none European users

Does it really matter? Just give all users a fair treatment.

Re: 2018 reform of EU data protection rules

#27

This guide does not clarify one important question: Does a company in the EU have to apply gdpr guidelines for none European users. If so, this would be a significant disadvantage for all European companies since their none European competitors obviously only have to comply for European users. One scenario in which this would be very relevant: A website needs to show a very long consent form to users that want to use…

If your company is located in the EU the regulation applies to all your users worldwide. Actually i don't think what you are suggesting is a big concern - people were predicting that about the cookie laws.

Re: 2018 reform of EU data protection rules

#28

This guide does not clarify one important question: Does a company in the EU have to apply gdpr guidelines for none European users. If so, this would be a significant disadvantage for all European companies since their none European competitors obviously only have to comply for European users. One scenario in which this would be very relevant: A website needs to show a very long consent form to users that want to use…

> This guide does not clarify one important question: Does a company in the EU have to apply gdpr guidelines for none European users.

Yes, the GDRP applies to anyone "in the Union". Someone on vacation from the US would be covered _while they are in the EU_.

If your company is based in the EU, then you must comply for all users, regardless of their current country or citizenship.

Re: 2018 reform of EU data protection rules

#29

This guide does not clarify one important question: Does a company in the EU have to apply gdpr guidelines for none European users. If so, this would be a significant disadvantage for all European companies since their none European competitors obviously only have to comply for European users. One scenario in which this would be very relevant: A website needs to show a very long consent form to users that want to use…

Maybe I'm just stupid, but that seems very clear to me from article 3.1 [0]:

This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not.

[0]: https://gdpr-info.eu/art-3-gdpr/

Post reply on HN