Earlier quoted context omitted.
Why do you think so? After you document/publish what information you pass to which network, what problems do you expect related to the ads?
Because I apparently need affirmative check-the-box consent before I can actually use those ad networks. I'm not doing anything shady: all the information I collect and why I collect it has always been in my privacy policy. But making people have to opt-in to see ads on the site is a big problem.
2018 reform of EU data protection rules
81–90 of 150 posts
Re: 2018 reform of EU data protection rules
#82PSA: Please make sure you're not relying on HN comments for your understanding of the GDPR if you're the one responsible in your organization. I need to get back to all the panicked questions CS has forwarded to me (the DPO equivalent for my company), but please understand that there's a lot of misunderstanding in every HN thread on this topic.
Besides honest misunderstanding, there's so much FUD being spread by people on HN who are afraid that their greedy data manipulation plan for a startup has been completely foiled...
So much FUD that you definitely feel sometimes that the comments are straight out of http://n-gate.com/
Caricaturizing (a bit):
"HN1: The GDPR takes away our freedom to make tons of money from your private data! Dirty EU commies and their superstate imposing their law worldwide!
HN2: The law doesn't apply worldwide and it protects my privacy. Just block users which are geographically in the EU. Also, read the law, it's only 60 page and more readable than most RFCs.
HN2: Nah, I'm good, I'll just rely on internet FUD as my main source of info. Dirty EU commie bureaucrats!"
PS: Obviously not all comments are misguided, but good God, there's soooooo many which miss the mark by a mile...
Re: 2018 reform of EU data protection rules
#83First, I am not a lawyer. I don't even play one on TV. The big question I keep hearing is; I'm in the US (or other non-EU country), does GDPR apply to my company or organization? The shortest possible answer is: Maybe :) The answer is: YES if your company has a physical or legal presence (like an office, employee, parent-company, subsidiary, etc.) in an EU country. The GDPR applies to you and you need to to start rea…
They explicitly contradict you. https://ec.europa.eu/info/law/law-topic/data-protection/refo... The law applies to... 2. a company established outside the EU offering goods/services (paid or for free) or monitoring the behaviour of individuals in the EU. Do you have any evidence? You're doing business with EU citizens. You allow them to connect to your site. Wouldn't this operate similarly to how extradition by the U…
Of course, if you ignore the EU repeatedly, you’re going to be stuck if you ever want to expand to the EU, or have any assets there ever. That’s about all they can do.
Re: 2018 reform of EU data protection rules
#84Enforcement factsheet: https://ec.europa.eu/commission/sites/beta-political/files/d... Pretty clearly primarily enforced by national regulatory agencies, who are the only ones who can apply fines . It mentions citizens taking companies to court, but https://ec.europa.eu/commission/sites/beta-political/files/d... says that's for monetary damages, not for fines. This is unchanged from previous laws. Can people stop fre…
> Your company is service provider based outside the EU. It provides services to customers outside the EU. Its clients can use its services when they travel to other countries, including within the EU. Provided your company doesn't specifically target its services at individuals in the EU, it is not subject to the rules of the GDPR.
(emphasis mine)
Re: 2018 reform of EU data protection rules
#85Earlier quoted context omitted.
you are vastly underestimating the ease of implementation
Depends on your business. I didn't find it as hard as PCI compliance for instance
Re: 2018 reform of EU data protection rules
#86PSA: Please make sure you're not relying on HN comments for your understanding of the GDPR if you're the one responsible in your organization. I need to get back to all the panicked questions CS has forwarded to me (the DPO equivalent for my company), but please understand that there's a lot of misunderstanding in every HN thread on this topic.
US readers: EU law is different from US law in that it is generally approachable and readable. While in the US it is difficult to even know which laws apply to you without the help of an experienced lawyer (because of case/precedent law), in the EU this is much easier. So don't be afraid to reach for the sources.
Re: 2018 reform of EU data protection rules
#87An important one to note as it's applicable to all businesses whose customers include EU residents because it addresses the collection and processing of their personal data locally and internationally.
This is not true. Just read the regulation. It's pretty clear that unless you're located in the EU or you're pursuing EU residents then the GDPR does not apply to you. Logically, it should be clear that the GDPR cannot apply to any business who an EU citizen stumbles upon and decides to buy something. The entire motivation of the GDPR is to prevent surveillance of EU residents with respect to their actions in the Uni…
Re: 2018 reform of EU data protection rules
#88Enforcement factsheet: https://ec.europa.eu/commission/sites/beta-political/files/d... Pretty clearly primarily enforced by national regulatory agencies, who are the only ones who can apply fines . It mentions citizens taking companies to court, but https://ec.europa.eu/commission/sites/beta-political/files/d... says that's for monetary damages, not for fines. This is unchanged from previous laws. Can people stop fre…
In Germany offenses against the GDPR can cause a "Abmahnung" which do not result in a fine but a charge. There a legions of filthy lawyers waiting for the 25.5.
"Abmahnungen" are cease and desist letters by the way.
Re: 2018 reform of EU data protection rules
#89> what is personal data > an Internet Protocol (IP) address; Told ya suckers for months. Keep believing they aren't at your risk. Previously: https://news.ycombinator.com/item?id=16910301
Re: 2018 reform of EU data protection rules
#90Can the average lawyer get rich off this? Can lawyer A (who is not affiliated with the EU government) sue Company B on behalf of the users and get a payday? For reference, I read a thread where a guy in my town sues businesses for violating the ADA and the settlement is like loser must fix steps and pay plaintiff some compensation. Maybe its this story or maybe its another guy: http://www.startribune.com/st-paul-land…