Live data from Hacker News

2018 reform of EU data protection rules

ec.europa.eu

101–110 of 150 posts

Re: 2018 reform of EU data protection rules

#101
post #82

PSA: Please make sure you're not relying on HN comments for your understanding of the GDPR if you're the one responsible in your organization. I need to get back to all the panicked questions CS has forwarded to me (the DPO equivalent for my company), but please understand that there's a lot of misunderstanding in every HN thread on this topic.

Heh, I'd say that it's even worse than "misunderstanding". Besides honest misunderstanding, there's so much FUD being spread by people on HN who are afraid that their greedy data manipulation plan for a startup has been completely foiled... So much FUD that you definitely feel sometimes that the comments are straight out of http://n-gate.com/ Caricaturizing (a bit): "HN1: The GDPR takes away our freedom to make tons…

[deleted]

Re: 2018 reform of EU data protection rules

#102

Earlier quoted context omitted.

Would the downvoters care to explain what offended them? Looking the other way does not help solve a problem.

Well, my immediate thoughts in response to that reply were: "Why is some extra law specific to Germany relevant to my comment? This is a discussion about the GDPR, not about national data protection laws."

It's not about national laws, it's about the implementation of the GDPR on a national level (namely C&D letters).

Re: 2018 reform of EU data protection rules

#103
post #93

Earlier quoted context omitted.

You could just remove parts of the IP address so it could no longer be used to identify a unique individual. For example, if you removed the last 3 digits, it could no longer be used on IP lookups (presumably), or an ISP would not be able to disclose the particular individual that is associated with the user account that the IP is linked to, because there is insufficient information available. Here's Google's approac…

Removing the last 3 digits would often uniquely identify a larger company or a city and if you only have 1 user from that city/company, those records would be easy to connect. Maybe Google is hoping the EU will accept that balance of concerns, but it doesn't sound like it realises the spirit of the law.

If your reference to 'you' means someone running a site who only has possession of a reduced IP address, then how would connection work?

Or are you saying that if I went to an ISP with the reduced IP address, they could disclose details of the person, if they only had 1 account within the range of IP addresses that the restricted IP address covered? This doesn't seem particularly likely to me? I thought ISPs hold a block of IPs and dole them out on that basis, and so resulting in only a loose connection between IP address and location?

On large companies, that would be out of scope, because whilst the reduced ISP may be linked to 1 large company, the assumption would be that the large company had multiple employees. On that basis although the account may be linked to a particular employee, no one employee could be singled out because multiple people would be relying on the same base IP potentially I would have thought?

Re: 2018 reform of EU data protection rules

#104

Earlier quoted context omitted.

Ok, let's assume this interpretation is correct. Targeted advertising will require explicit user consent under gdpr since pii is collected. It's fair to assume that there is no big incentive for a user of a website to consent to targeted ads. Targeted ads are usually way way more profitable that contextual ads. If you are a large publisher, would you really want to have your company in the EU in future?

They're only way more profitable right now because they exist. I guess if you want to sell something the EU has pretty much banned, basing your business inside the EU won't work.

How can an alternative be more profitable? Targeted ads allow to TARGET someone. That means that instead of wasting views on someone that won't be interested (and thus, be a waste of money) you use it on people that will care.

For sure if you have 5$ of budget per sale, if it takes 1000 views to get a sale or 1 views, you won't pay the same for views in both situation depending on the efficiency of the ad.

Re: 2018 reform of EU data protection rules

#105

Earlier quoted context omitted.

Where would "non-targeted" ads even come from? How can you use an ad network or even run a standard ad server in a way that doesn't share at least the reader's IP Address? Mom and pop publishers who don't have the resources or ability to staff their own ad sales team are going to be in trouble. The big players who can work around this obstacle are going to be fine. I'm not happy about this.

IP address is only personally identifable info if it is coupled with other info that links it to a real person. Storing an IP address by itself and sharing it is not, by itself PII

No, I'm pretty sure that is incorrect. The EU believes that an IP itself is personally identifiable and it must be secured and processed like any PII [1]. I think you could make a case that the IP being sent to an ad network is an "acceptable" business practice for which you don't need consent, but IANAL.

[1] https://www.enterprisetimes.co.uk/2016/10/20/ecj-rules-ip-ad...

Re: 2018 reform of EU data protection rules

#106

How does this affect server logs? Under the "what is personal data" section they list ip addresses as personal data.

Do you have a legitimate reason for storing that data? Probably not, so just stop it from being logged.

Yes. One of the key parts of GDPR is breach reporting. Assume you discover your company has been breached. How do you investigate the breach? Discover who was impacted, what was done and by whom? Is that significantly harder/impossible if your logs don't contain IP addresses?

Edit: Also consider Log retention. Yahoo discovered a data breach 3 years after it happened. What if they'd only kept logs for 1 year.

Re: 2018 reform of EU data protection rules

#107

How does this affect server logs? Under the "what is personal data" section they list ip addresses as personal data.

Do you have a legitimate reason for storing that data? Probably not, so just stop it from being logged.

Never have been in a DDOS attack? Good luck doing anything without getting the IP.

It's useful to know where the requests come from too. You get a bunch of request from IP that come from a specific peer and that peer is saturated? How could you verify that without a log? You want to add CDN to the right locations. Where should you?

Really, I think it's just make more sense for any small company to block EU and when you have the means to do it correctly (with the help of a competent DPO), then yeah add that EU in your market.

Re: 2018 reform of EU data protection rules

#108
post #86

PSA: Please make sure you're not relying on HN comments for your understanding of the GDPR if you're the one responsible in your organization. I need to get back to all the panicked questions CS has forwarded to me (the DPO equivalent for my company), but please understand that there's a lot of misunderstanding in every HN thread on this topic.

And it's not just HN. I've listened to at least three podcasts by now where "well-known figures" offer advice that is just plain wrong. US readers: EU law is different from US law in that it is generally approachable and readable. While in the US it is difficult to even know which laws apply to you without the help of an experienced lawyer (because of case/precedent law), in the EU this is much easier. So don't be af…

The fact that there's so much confusion suggests that it is not that easy to understand.

I've read it and I'm still confused. Without caselaw and a lawyer how am I to determine which data processing are considered "legitimate interest" in Article 6? Recital 47 is supposed to clarify this, but it's still pretty vague and it says legitimate interests may provide a legal basis for processing. May? How do I know if they do or do not?

Re: 2018 reform of EU data protection rules

#109
post #82

PSA: Please make sure you're not relying on HN comments for your understanding of the GDPR if you're the one responsible in your organization. I need to get back to all the panicked questions CS has forwarded to me (the DPO equivalent for my company), but please understand that there's a lot of misunderstanding in every HN thread on this topic.

Heh, I'd say that it's even worse than "misunderstanding". Besides honest misunderstanding, there's so much FUD being spread by people on HN who are afraid that their greedy data manipulation plan for a startup has been completely foiled... So much FUD that you definitely feel sometimes that the comments are straight out of http://n-gate.com/ Caricaturizing (a bit): "HN1: The GDPR takes away our freedom to make tons…

Please do not violate the Prime Directive. Thanks.

Re: 2018 reform of EU data protection rules

#110

Enforcement factsheet: https://ec.europa.eu/commission/sites/beta-political/files/d... Pretty clearly primarily enforced by national regulatory agencies, who are the only ones who can apply fines . It mentions citizens taking companies to court, but https://ec.europa.eu/commission/sites/beta-political/files/d... says that's for monetary damages, not for fines. This is unchanged from previous laws. Can people stop fre…

And: > Your company is service provider based outside the EU. It provides services to customers outside the EU. Its clients can use its services when they travel to other countries, including within the EU. Provided your company doesn't specifically target its services at individuals in the EU, it is not subject to the rules of the GDPR. (emphasis mine)

Correct me if I'm wrong, but I think that changes as soon as you have one paying customer located in the EU (even if you were not specifically targeting the EU).

I would guess most people selling something on the internet have at least some small percentage of customers in the EU.

Post reply on HN