Live data from Hacker News

2018 reform of EU data protection rules

ec.europa.eu

31–40 of 150 posts

Re: 2018 reform of EU data protection rules

#31

And for a nice easy to read version of the regulation; http://gdpr-info.eu/

With the minor caveat that gdpr-info.eu looks official due to the .eu domain, but is actually run by 'intersoft consulting services AG' as advertising for their consulting service (the content is just the laws of course)

Re: 2018 reform of EU data protection rules

#32

This guide does not clarify one important question: Does a company in the EU have to apply gdpr guidelines for none European users. If so, this would be a significant disadvantage for all European companies since their none European competitors obviously only have to comply for European users. One scenario in which this would be very relevant: A website needs to show a very long consent form to users that want to use…

If your company is located in the EU the regulation applies to all your users worldwide. Actually i don't think what you are suggesting is a big concern - people were predicting that about the cookie laws.

I think the guidelines for cookie laws are not comparable, since gdpr required explicit checking a box until the service can be provided as opposed to a not very intrusive box in the footer.

Re: 2018 reform of EU data protection rules

#33
post #29

This guide does not clarify one important question: Does a company in the EU have to apply gdpr guidelines for none European users. If so, this would be a significant disadvantage for all European companies since their none European competitors obviously only have to comply for European users. One scenario in which this would be very relevant: A website needs to show a very long consent form to users that want to use…

Maybe I'm just stupid, but that seems very clear to me from article 3.1 [0]: This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not. [0]: https://gdpr-info.eu/art-3-gdpr/

AFAIK that simply means that GDPR applies even if your servers are in the US (or anywhere else outside of the EU).

Re: 2018 reform of EU data protection rules

#34
post #6

Earlier quoted context omitted.

I honestly can't wait to ask my local retailer what data they have on me based on their loyalty cards. So far they were exempt from data disclosure laws because they were not an IT company.

I would assume that he has all the data on you, you ever gave him. What else did you do expect when you signed up for the loyalty program?

> him

I think we're probably talking about national chains here.

I would imagine stores will use the loyalty cards to profile users, and if they've every stored any of the profiling data then this data will be the data you will be getting.

Re: 2018 reform of EU data protection rules

#35
post #29

This guide does not clarify one important question: Does a company in the EU have to apply gdpr guidelines for none European users. If so, this would be a significant disadvantage for all European companies since their none European competitors obviously only have to comply for European users. One scenario in which this would be very relevant: A website needs to show a very long consent form to users that want to use…

Maybe I'm just stupid, but that seems very clear to me from article 3.1 [0]: This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not. [0]: https://gdpr-info.eu/art-3-gdpr/

Ok, let's assume this interpretation is correct.

Targeted advertising will require explicit user consent under gdpr since pii is collected. It's fair to assume that there is no big incentive for a user of a website to consent to targeted ads. Targeted ads are usually way way more profitable that contextual ads. If you are a large publisher, would you really want to have your company in the EU in future?

Re: 2018 reform of EU data protection rules

#36
post #10

Earlier quoted context omitted.

I do not believe that is correct. Right now, for example, if you are a US business with no offices or employees in EU jurisdiction then there is little the EU can do if you are not GDPR compliant - regardless of whether you deal with EU traffic or not. The EU might wish their laws were global, but that doesn’t make it so. #notalawyer

You're not wrong, but, what internet company doesn't operate within the EU? If you operate in the EU, and handle EU citizen's data, you have to conform to the GDPR. I don't think there's many internet companies that would not serve the EU because of it. Although, Google did pull out of China due to the censorship demands and the like.

Hmm. You just agreed with me and then disagreed me :)

Again, I say this as someone who is implementing GDPR for a US-based company, and is also a EU citizen (Irish) and has sat more meetings with various legal groups than I care to remember (again, stress I'm not a lawyer).

It is all about a companies appetite for risk and how tied the are __PHYSICALLY__ to the EU (offices/employees/parent-companies/subsidiaries).

This also gets into areas of Extraterritorial Jurisdiction. Any country can claim this over any other territory they wish. But, for the claim to be effective (except by use of force), it must be agreed either with the legal authority of the country.

Right now there appears to be none. No one is clearly citing any treaty with the EU as giving them this authority.

Re: 2018 reform of EU data protection rules

#37
post #10

Earlier quoted context omitted.

I do not believe that is correct. Right now, for example, if you are a US business with no offices or employees in EU jurisdiction then there is little the EU can do if you are not GDPR compliant - regardless of whether you deal with EU traffic or not. The EU might wish their laws were global, but that doesn’t make it so. #notalawyer

You're not wrong, but, what internet company doesn't operate within the EU? If you operate in the EU, and handle EU citizen's data, you have to conform to the GDPR. I don't think there's many internet companies that would not serve the EU because of it. Although, Google did pull out of China due to the censorship demands and the like.

Just to clarify, as I learned this the other day, it's not about EU citizenship, but about being "in the Union". A resident alien is covered as are vacationers, but only while they are physically in the EU.

Re: 2018 reform of EU data protection rules

#39

Enforcement factsheet: https://ec.europa.eu/commission/sites/beta-political/files/d... Pretty clearly primarily enforced by national regulatory agencies, who are the only ones who can apply fines . It mentions citizens taking companies to court, but https://ec.europa.eu/commission/sites/beta-political/files/d... says that's for monetary damages, not for fines. This is unchanged from previous laws. Can people stop fre…

Great site that summarises GDRP in plain english: https://blog.varonis.com/gdpr-requirements-list-in-plain-eng...

Re: 2018 reform of EU data protection rules

#40

Earlier quoted context omitted.

If your company is located in the EU the regulation applies to all your users worldwide. Actually i don't think what you are suggesting is a big concern - people were predicting that about the cookie laws.

I think the guidelines for cookie laws are not comparable, since gdpr required explicit checking a box until the service can be provided as opposed to a not very intrusive box in the footer.

> gdpr required explicit checking a box until the service can be provided

You don't need opt-in for things that are essential to providing the service. You need that for non-essential data storage and sharing. Unless you want to make providing your service conditional on extra collection, what you describe shouldn't be necessary.

Post reply on HN