Live data from Hacker News

2018 reform of EU data protection rules

ec.europa.eu

41–50 of 150 posts

Re: 2018 reform of EU data protection rules

#41

Enforcement factsheet: https://ec.europa.eu/commission/sites/beta-political/files/d... Pretty clearly primarily enforced by national regulatory agencies, who are the only ones who can apply fines . It mentions citizens taking companies to court, but https://ec.europa.eu/commission/sites/beta-political/files/d... says that's for monetary damages, not for fines. This is unchanged from previous laws. Can people stop fre…

Also:

https://ec.europa.eu/info/law/law-topic/data-protection/refo...

The authority must ensure that fines imposed in each individual case are effective, proportionate and dissuasive. It will take into account a number of factors such as the nature, gravity and duration of the infringement, its intentional or negligent character, any action taken to mitigate the damage suffered by individuals, the degree of cooperation of the organisation, etc.

Re: 2018 reform of EU data protection rules

#42

Earlier quoted context omitted.

If your company is located in the EU the regulation applies to all your users worldwide. Actually i don't think what you are suggesting is a big concern - people were predicting that about the cookie laws.

I think the guidelines for cookie laws are not comparable, since gdpr required explicit checking a box until the service can be provided as opposed to a not very intrusive box in the footer.

[deleted]

Re: 2018 reform of EU data protection rules

#43

This guide does not clarify one important question: Does a company in the EU have to apply gdpr guidelines for none European users. If so, this would be a significant disadvantage for all European companies since their none European competitors obviously only have to comply for European users. One scenario in which this would be very relevant: A website needs to show a very long consent form to users that want to use…

> This guide does not clarify one important question: Does a company in the EU have to apply gdpr guidelines for none European users Does it really matter? Just give all users a fair treatment.

+1 for fair user treatment, but the way the laws are written, companies that serve users globally from within the EU will have a hard time competing with their international competitors under the new regulation. I just wonder if European law makers have thought this through.

Re: 2018 reform of EU data protection rules

#44
This is a great resource because it is from the EU, provides clear examples, cites the actual legislation and Article 29 Working Party Guidelines (which is the group that is tasked with preparing official opinions on GDPR).

I think that if you want to really comprehend something, you should go to the primary source. The GDPR legislation is far more approachable than it seems (as an official 261 page PDF). When the preamble and the mechanical bits about how the GDPR will be governed are removed, the parts that important to companies are only 34 pages long. You can use this to guide your reading: https://www.enterpriseready.io/gdpr/how-to-read-gdpr/

Re: 2018 reform of EU data protection rules

#45
post #38

Nice guidelines, seems like for most small businesses it will be straight forward to be GDPR compliant

Maybe if you don't have ads on your site, otherwise its going to be a problem.

Why do you think so? After you document/publish what information you pass to which network, what problems do you expect related to the ads?

Re: 2018 reform of EU data protection rules

#46
First, I am not a lawyer. I don't even play one on TV.

The big question I keep hearing is; I'm in the US (or other non-EU country), does GDPR apply to my company or organization?

The shortest possible answer is: Maybe :)

The answer is: YES if your company has a physical or legal presence (like an office, employee, parent-company, subsidiary, etc.) in an EU country. The GDPR applies to you and you need to to start reading up ASAP as you only have a few weeks to figure this all out.

The answer is likley: NO (but be careful here) if you have no physical or legal presence in the EU. Bonus points if your business isn't really aimed at the EU.

The answer is likley still: NO if again, you have no physical or legal presence in the EU but do rely on EU traffic as a direct or significant part of your business. At that point is all about how much risk you're willing to take on as we see how this law is interpreted.

Any country can claim this over any other territory they wish. But that doesn't make it true. For the claim to be effective (except by use of force), it must be agreed either with the legal authority of the country.

Right now there appears to be none. No one is clearly citing any treaty with the EU as giving them this authority.

  Disclaimer: This isn't legal advice. This is my personal view 
  on a complicated issue that I'm trying to discuss in order 
  to learn more myself.

Re: 2018 reform of EU data protection rules

#47
post #29

Earlier quoted context omitted.

Maybe I'm just stupid, but that seems very clear to me from article 3.1 [0]: This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not. [0]: https://gdpr-info.eu/art-3-gdpr/

Ok, let's assume this interpretation is correct. Targeted advertising will require explicit user consent under gdpr since pii is collected. It's fair to assume that there is no big incentive for a user of a website to consent to targeted ads. Targeted ads are usually way way more profitable that contextual ads. If you are a large publisher, would you really want to have your company in the EU in future?

They're only way more profitable right now because they exist. I guess if you want to sell something the EU has pretty much banned, basing your business inside the EU won't work.

Re: 2018 reform of EU data protection rules

#48

Earlier quoted context omitted.

> This guide does not clarify one important question: Does a company in the EU have to apply gdpr guidelines for none European users Does it really matter? Just give all users a fair treatment.

+1 for fair user treatment, but the way the laws are written, companies that serve users globally from within the EU will have a hard time competing with their international competitors under the new regulation. I just wonder if European law makers have thought this through.

I think in the current situation, having strong privacy for all users will be a feature you can bring to the market, especially for US users it can be a big plus since the US doesn't have any comparable privacy law.

Re: 2018 reform of EU data protection rules

#50
post #46

First, I am not a lawyer. I don't even play one on TV. The big question I keep hearing is; I'm in the US (or other non-EU country), does GDPR apply to my company or organization? The shortest possible answer is: Maybe :) The answer is: YES if your company has a physical or legal presence (like an office, employee, parent-company, subsidiary, etc.) in an EU country. The GDPR applies to you and you need to to start rea…

I think the problem for orgs in non EU and non Third Countries is that a lot of EU based orgs will be (or already done so) moving as much as possible to providers that are GDPR compliant - or offer assurances that satisfy the GDPR (Like the Privacy Shield)

So by not being compliant, or at least offering a way for orgs that are compelled to follow GDPR to be compliant, they will start to miss out on business from B2B or B2C.

Especially after May 25th, there are already radio and TV adverts about it here in the UK, and I imagine that a lot of consumers are going to start questioning this before they use a service

Post reply on HN