Live data from Hacker News

2018 reform of EU data protection rules

ec.europa.eu

51–60 of 150 posts

Re: 2018 reform of EU data protection rules

#54

And for a nice easy to read version of the regulation; http://gdpr-info.eu/

With the minor caveat that gdpr-info.eu looks official due to the .eu domain, but is actually run by 'intersoft consulting services AG' as advertising for their consulting service (the content is just the laws of course)

True. (although I wouldn't associate .eu with anything being official)

I just like it as it is broken up nicely and has links to any relevant recitals and deregations etc

Re: 2018 reform of EU data protection rules

#55
post #46

First, I am not a lawyer. I don't even play one on TV. The big question I keep hearing is; I'm in the US (or other non-EU country), does GDPR apply to my company or organization? The shortest possible answer is: Maybe :) The answer is: YES if your company has a physical or legal presence (like an office, employee, parent-company, subsidiary, etc.) in an EU country. The GDPR applies to you and you need to to start rea…

I think the problem for orgs in non EU and non Third Countries is that a lot of EU based orgs will be (or already done so) moving as much as possible to providers that are GDPR compliant - or offer assurances that satisfy the GDPR (Like the Privacy Shield) So by not being compliant, or at least offering a way for orgs that are compelled to follow GDPR to be compliant, they will start to miss out on business from B2B…

Yes - and I hope they do!

I'm a big fan of this law, but I also see a lot of panic and inaccurate claims being made.

Re: 2018 reform of EU data protection rules

#56
post #46

First, I am not a lawyer. I don't even play one on TV. The big question I keep hearing is; I'm in the US (or other non-EU country), does GDPR apply to my company or organization? The shortest possible answer is: Maybe :) The answer is: YES if your company has a physical or legal presence (like an office, employee, parent-company, subsidiary, etc.) in an EU country. The GDPR applies to you and you need to to start rea…

They explicitly contradict you.

https://ec.europa.eu/info/law/law-topic/data-protection/refo...

The law applies to... 2. a company established outside the EU offering goods/services (paid or for free) or monitoring the behaviour of individuals in the EU.

Do you have any evidence? You're doing business with EU citizens. You allow them to connect to your site.

Wouldn't this operate similarly to how extradition by the US of foreign hackers work?

Re: 2018 reform of EU data protection rules

#57
post #33
post #29

Earlier quoted context omitted.

Maybe I'm just stupid, but that seems very clear to me from article 3.1 [0]: This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not. [0]: https://gdpr-info.eu/art-3-gdpr/

AFAIK that simply means that GDPR applies even if your servers are in the US (or anywhere else outside of the EU).

No, that's what article 3.2 means:

This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to:

- the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or

- the monitoring of their behaviour as far as their behaviour takes place within the Union.

Re: 2018 reform of EU data protection rules

#58
PSA: Please make sure you're not relying on HN comments for your understanding of the GDPR if you're the one responsible in your organization. I need to get back to all the panicked questions CS has forwarded to me (the DPO equivalent for my company), but please understand that there's a lot of misunderstanding in every HN thread on this topic.

Re: 2018 reform of EU data protection rules

#59

Enforcement factsheet: https://ec.europa.eu/commission/sites/beta-political/files/d... Pretty clearly primarily enforced by national regulatory agencies, who are the only ones who can apply fines . It mentions citizens taking companies to court, but https://ec.europa.eu/commission/sites/beta-political/files/d... says that's for monetary damages, not for fines. This is unchanged from previous laws. Can people stop fre…

In Germany offenses against the GDPR can cause a "Abmahnung" which do not result in a fine but a charge. There a legions of filthy lawyers waiting for the 25.5.

This is a big problem here in Germany and might very well be a reason to shut down my site on 5/24.

Re: 2018 reform of EU data protection rules

#60
post #2

An important one to note as it's applicable to all businesses whose customers include EU residents because it addresses the collection and processing of their personal data locally and internationally.

This is not true. Just read the regulation. It's pretty clear that unless you're located in the EU or you're pursuing EU residents then the GDPR does not apply to you. Logically, it should be clear that the GDPR cannot apply to any business who an EU citizen stumbles upon and decides to buy something. The entire motivation of the GDPR is to prevent surveillance of EU residents with respect to their actions in the Union.
Post reply on HN