Live data from Hacker News

2018 reform of EU data protection rules

ec.europa.eu

71–80 of 150 posts

Re: 2018 reform of EU data protection rules

#71

Enforcement factsheet: https://ec.europa.eu/commission/sites/beta-political/files/d... Pretty clearly primarily enforced by national regulatory agencies, who are the only ones who can apply fines . It mentions citizens taking companies to court, but https://ec.europa.eu/commission/sites/beta-political/files/d... says that's for monetary damages, not for fines. This is unchanged from previous laws. Can people stop fre…

In Germany offenses against the GDPR can cause a "Abmahnung" which do not result in a fine but a charge. There a legions of filthy lawyers waiting for the 25.5.

[deleted]

Re: 2018 reform of EU data protection rules

#73
post #46

First, I am not a lawyer. I don't even play one on TV. The big question I keep hearing is; I'm in the US (or other non-EU country), does GDPR apply to my company or organization? The shortest possible answer is: Maybe :) The answer is: YES if your company has a physical or legal presence (like an office, employee, parent-company, subsidiary, etc.) in an EU country. The GDPR applies to you and you need to to start rea…

Where are you getting the physical or legal presence requirement from? I don't think that's correct.

Re: 2018 reform of EU data protection rules

#74
post #67

This guide does not clarify one important question: Does a company in the EU have to apply gdpr guidelines for none European users. If so, this would be a significant disadvantage for all European companies since their none European competitors obviously only have to comply for European users. One scenario in which this would be very relevant: A website needs to show a very long consent form to users that want to use…

This is probably going to happen, yeah. It will however likely also establish European companies as particularly secure and trustworthy. For a long time already, it's been common practice to avoid Chinese services, because of the surveillance that the Chinese government does. And there's a growing number of people who avoid US-based services, too. The recent CLOUD Act certainly doesn't weakening their position either…

It also gives some non-eu based companies the same secure and trustworthy benefits. They just need to have an obvious presence in the EU, and not check if someone is in the EU when they are asked to apply GDPR.

Re: 2018 reform of EU data protection rules

#76
post #46

First, I am not a lawyer. I don't even play one on TV. The big question I keep hearing is; I'm in the US (or other non-EU country), does GDPR apply to my company or organization? The shortest possible answer is: Maybe :) The answer is: YES if your company has a physical or legal presence (like an office, employee, parent-company, subsidiary, etc.) in an EU country. The GDPR applies to you and you need to to start rea…

They explicitly contradict you. https://ec.europa.eu/info/law/law-topic/data-protection/refo... The law applies to... 2. a company established outside the EU offering goods/services (paid or for free) or monitoring the behaviour of individuals in the EU. Do you have any evidence? You're doing business with EU citizens. You allow them to connect to your site. Wouldn't this operate similarly to how extradition by the U…

It does not matter what EU thinks. What matters if what can EU do and the answer is nothing unless your company operates in Europe

> Wouldn't this operate similarly to how extradition by the US of foreign hackers work?

It would not.

Re: 2018 reform of EU data protection rules

#77

PSA: Please make sure you're not relying on HN comments for your understanding of the GDPR if you're the one responsible in your organization. I need to get back to all the panicked questions CS has forwarded to me (the DPO equivalent for my company), but please understand that there's a lot of misunderstanding in every HN thread on this topic.

To generalise this, there's a lot of misunderstanding in every HN thread on most every topic.

Re: 2018 reform of EU data protection rules

#78
post #75

How does this affect server logs? Under the "what is personal data" section they list ip addresses as personal data.

Don't log ip addresses, or anonymise them.

How would you anonymise an IPv4 address? Hashing isn't enough, because that would be easy to brute force. And you can't create a table mapping IPs to anonymized-IPs, because then you are still storing them.

Re: 2018 reform of EU data protection rules

#79
Can the average lawyer get rich off this?

Can lawyer A (who is not affiliated with the EU government) sue Company B on behalf of the users and get a payday?

For reference, I read a thread where a guy in my town sues businesses for violating the ADA and the settlement is like loser must fix steps and pay plaintiff some compensation. Maybe its this story or maybe its another guy: http://www.startribune.com/st-paul-landlord-wins-case-agains... , actually I think its this guy http://www.startribune.com/doctor-lawyer-wheelchair-user-it-...

Re: 2018 reform of EU data protection rules

#80
post #11

Earlier quoted context omitted.

I always lose my loyalty card from time to time (it doesn't have any loyalty advantages you just have to have it to get the discounts) and ask for a new one. I wonder if they were able to link them back together

Unless you always pay cash - it should be trivial to link by the payment card number.

Do they actually see a card number? Anyway, I have a couple and I have a habit of losing/breaking those as well. I'm just really bad at holding on to cards it seems
Post reply on HN