Live data from Hacker News

2018 reform of EU data protection rules

ec.europa.eu

81–90 of 150 posts

Re: 2018 reform of EU data protection rules

#81

Earlier quoted context omitted.

Why do you think so? After you document/publish what information you pass to which network, what problems do you expect related to the ads?

Because I apparently need affirmative check-the-box consent before I can actually use those ad networks. I'm not doing anything shady: all the information I collect and why I collect it has always been in my privacy policy. But making people have to opt-in to see ads on the site is a big problem.

You can do non-targetted ads without explicit consent as far as I understand. You only need it for the extra personal information use. Sure it's a bit worse for the publishers. (But I'm happy with that)

Re: 2018 reform of EU data protection rules

#82

PSA: Please make sure you're not relying on HN comments for your understanding of the GDPR if you're the one responsible in your organization. I need to get back to all the panicked questions CS has forwarded to me (the DPO equivalent for my company), but please understand that there's a lot of misunderstanding in every HN thread on this topic.

Heh, I'd say that it's even worse than "misunderstanding".

Besides honest misunderstanding, there's so much FUD being spread by people on HN who are afraid that their greedy data manipulation plan for a startup has been completely foiled...

So much FUD that you definitely feel sometimes that the comments are straight out of http://n-gate.com/

Caricaturizing (a bit):

"HN1: The GDPR takes away our freedom to make tons of money from your private data! Dirty EU commies and their superstate imposing their law worldwide!

HN2: The law doesn't apply worldwide and it protects my privacy. Just block users which are geographically in the EU. Also, read the law, it's only 60 page and more readable than most RFCs.

HN2: Nah, I'm good, I'll just rely on internet FUD as my main source of info. Dirty EU commie bureaucrats!"

PS: Obviously not all comments are misguided, but good God, there's soooooo many which miss the mark by a mile...

Re: 2018 reform of EU data protection rules

#83
post #46

First, I am not a lawyer. I don't even play one on TV. The big question I keep hearing is; I'm in the US (or other non-EU country), does GDPR apply to my company or organization? The shortest possible answer is: Maybe :) The answer is: YES if your company has a physical or legal presence (like an office, employee, parent-company, subsidiary, etc.) in an EU country. The GDPR applies to you and you need to to start rea…

They explicitly contradict you. https://ec.europa.eu/info/law/law-topic/data-protection/refo... The law applies to... 2. a company established outside the EU offering goods/services (paid or for free) or monitoring the behaviour of individuals in the EU. Do you have any evidence? You're doing business with EU citizens. You allow them to connect to your site. Wouldn't this operate similarly to how extradition by the U…

In most countries, extradition requires that you’re being charged with a crime in another country with something for which you could also be charged in your current country, and which carries a one year prison sentence. If you’re not breaking the law in America, you have nothing to worry about. (This is at least the case for the UK-US treaty - I’ve not verified for other treaties, but I’d highly doubt the US would agree to a treaty with anyone which requires them to extradite anyone for something that isn’t a crime in the US.)

Of course, if you ignore the EU repeatedly, you’re going to be stuck if you ever want to expand to the EU, or have any assets there ever. That’s about all they can do.

Re: 2018 reform of EU data protection rules

#84

Enforcement factsheet: https://ec.europa.eu/commission/sites/beta-political/files/d... Pretty clearly primarily enforced by national regulatory agencies, who are the only ones who can apply fines . It mentions citizens taking companies to court, but https://ec.europa.eu/commission/sites/beta-political/files/d... says that's for monetary damages, not for fines. This is unchanged from previous laws. Can people stop fre…

And:

> Your company is service provider based outside the EU. It provides services to customers outside the EU. Its clients can use its services when they travel to other countries, including within the EU. Provided your company doesn't specifically target its services at individuals in the EU, it is not subject to the rules of the GDPR.

(emphasis mine)

Re: 2018 reform of EU data protection rules

#85

Earlier quoted context omitted.

you are vastly underestimating the ease of implementation

Depends on your business. I didn't find it as hard as PCI compliance for instance

Unless you actually maintain full payment account numbers, PCI compliance pretty much boils down to "I pinky-swear I'm not doing anything wrong" and the rules have virtually no teeth.

Re: 2018 reform of EU data protection rules

#86

PSA: Please make sure you're not relying on HN comments for your understanding of the GDPR if you're the one responsible in your organization. I need to get back to all the panicked questions CS has forwarded to me (the DPO equivalent for my company), but please understand that there's a lot of misunderstanding in every HN thread on this topic.

And it's not just HN. I've listened to at least three podcasts by now where "well-known figures" offer advice that is just plain wrong.

US readers: EU law is different from US law in that it is generally approachable and readable. While in the US it is difficult to even know which laws apply to you without the help of an experienced lawyer (because of case/precedent law), in the EU this is much easier. So don't be afraid to reach for the sources.

Re: 2018 reform of EU data protection rules

#87
post #60
post #2

An important one to note as it's applicable to all businesses whose customers include EU residents because it addresses the collection and processing of their personal data locally and internationally.

This is not true. Just read the regulation. It's pretty clear that unless you're located in the EU or you're pursuing EU residents then the GDPR does not apply to you. Logically, it should be clear that the GDPR cannot apply to any business who an EU citizen stumbles upon and decides to buy something. The entire motivation of the GDPR is to prevent surveillance of EU residents with respect to their actions in the Uni…

Mechanisms of enforcement is another discussion but the regulation clearly asserts the scope of data protection as global; it's applicable to all foreign companies processing data of EU residents, whether the companies are based in the EU or not.

Re: 2018 reform of EU data protection rules

#88

Enforcement factsheet: https://ec.europa.eu/commission/sites/beta-political/files/d... Pretty clearly primarily enforced by national regulatory agencies, who are the only ones who can apply fines . It mentions citizens taking companies to court, but https://ec.europa.eu/commission/sites/beta-political/files/d... says that's for monetary damages, not for fines. This is unchanged from previous laws. Can people stop fre…

In Germany offenses against the GDPR can cause a "Abmahnung" which do not result in a fine but a charge. There a legions of filthy lawyers waiting for the 25.5.

I don't think that's possible. Do you have a source to back that up? (Also, they don't automatically result in a charge.)

"Abmahnungen" are cease and desist letters by the way.

Re: 2018 reform of EU data protection rules

#89

> what is personal data > an Internet Protocol (IP) address; Told ya suckers for months. Keep believing they aren't at your risk. Previously: https://news.ycombinator.com/item?id=16910301

Can't wait for the pile of lawsuits to appear over this one

Re: 2018 reform of EU data protection rules

#90

Can the average lawyer get rich off this? Can lawyer A (who is not affiliated with the EU government) sue Company B on behalf of the users and get a payday? For reference, I read a thread where a guy in my town sues businesses for violating the ADA and the settlement is like loser must fix steps and pay plaintiff some compensation. Maybe its this story or maybe its another guy: http://www.startribune.com/st-paul-land…

Sue every European company on the basis of logging IPs, should be free money for lawyers
Post reply on HN