PSA: Please make sure you're not relying on HN comments for your understanding of the GDPR if you're the one responsible in your organization. I need to get back to all the panicked questions CS has forwarded to me (the DPO equivalent for my company), but please understand that there's a lot of misunderstanding in every HN thread on this topic.
Heh, I'd say that it's even worse than "misunderstanding". Besides honest misunderstanding, there's so much FUD being spread by people on HN who are afraid that their greedy data manipulation plan for a startup has been completely foiled... So much FUD that you definitely feel sometimes that the comments are straight out of http://n-gate.com/ Caricaturizing (a bit): "HN1: The GDPR takes away our freedom to make tons…
2018 reform of EU data protection rules
101–110 of 150 posts
Re: 2018 reform of EU data protection rules
#102Earlier quoted context omitted.
Would the downvoters care to explain what offended them? Looking the other way does not help solve a problem.
Well, my immediate thoughts in response to that reply were: "Why is some extra law specific to Germany relevant to my comment? This is a discussion about the GDPR, not about national data protection laws."
Re: 2018 reform of EU data protection rules
#103Earlier quoted context omitted.
You could just remove parts of the IP address so it could no longer be used to identify a unique individual. For example, if you removed the last 3 digits, it could no longer be used on IP lookups (presumably), or an ISP would not be able to disclose the particular individual that is associated with the user account that the IP is linked to, because there is insufficient information available. Here's Google's approac…
Removing the last 3 digits would often uniquely identify a larger company or a city and if you only have 1 user from that city/company, those records would be easy to connect. Maybe Google is hoping the EU will accept that balance of concerns, but it doesn't sound like it realises the spirit of the law.
Or are you saying that if I went to an ISP with the reduced IP address, they could disclose details of the person, if they only had 1 account within the range of IP addresses that the restricted IP address covered? This doesn't seem particularly likely to me? I thought ISPs hold a block of IPs and dole them out on that basis, and so resulting in only a loose connection between IP address and location?
On large companies, that would be out of scope, because whilst the reduced ISP may be linked to 1 large company, the assumption would be that the large company had multiple employees. On that basis although the account may be linked to a particular employee, no one employee could be singled out because multiple people would be relying on the same base IP potentially I would have thought?
Re: 2018 reform of EU data protection rules
#104Earlier quoted context omitted.
Ok, let's assume this interpretation is correct. Targeted advertising will require explicit user consent under gdpr since pii is collected. It's fair to assume that there is no big incentive for a user of a website to consent to targeted ads. Targeted ads are usually way way more profitable that contextual ads. If you are a large publisher, would you really want to have your company in the EU in future?
They're only way more profitable right now because they exist. I guess if you want to sell something the EU has pretty much banned, basing your business inside the EU won't work.
For sure if you have 5$ of budget per sale, if it takes 1000 views to get a sale or 1 views, you won't pay the same for views in both situation depending on the efficiency of the ad.
Re: 2018 reform of EU data protection rules
#105Earlier quoted context omitted.
Where would "non-targeted" ads even come from? How can you use an ad network or even run a standard ad server in a way that doesn't share at least the reader's IP Address? Mom and pop publishers who don't have the resources or ability to staff their own ad sales team are going to be in trouble. The big players who can work around this obstacle are going to be fine. I'm not happy about this.
IP address is only personally identifable info if it is coupled with other info that links it to a real person. Storing an IP address by itself and sharing it is not, by itself PII
[1] https://www.enterprisetimes.co.uk/2016/10/20/ecj-rules-ip-ad...
Re: 2018 reform of EU data protection rules
#106How does this affect server logs? Under the "what is personal data" section they list ip addresses as personal data.
Do you have a legitimate reason for storing that data? Probably not, so just stop it from being logged.
Edit: Also consider Log retention. Yahoo discovered a data breach 3 years after it happened. What if they'd only kept logs for 1 year.
Re: 2018 reform of EU data protection rules
#107How does this affect server logs? Under the "what is personal data" section they list ip addresses as personal data.
Do you have a legitimate reason for storing that data? Probably not, so just stop it from being logged.
It's useful to know where the requests come from too. You get a bunch of request from IP that come from a specific peer and that peer is saturated? How could you verify that without a log? You want to add CDN to the right locations. Where should you?
Really, I think it's just make more sense for any small company to block EU and when you have the means to do it correctly (with the help of a competent DPO), then yeah add that EU in your market.
Re: 2018 reform of EU data protection rules
#108PSA: Please make sure you're not relying on HN comments for your understanding of the GDPR if you're the one responsible in your organization. I need to get back to all the panicked questions CS has forwarded to me (the DPO equivalent for my company), but please understand that there's a lot of misunderstanding in every HN thread on this topic.
And it's not just HN. I've listened to at least three podcasts by now where "well-known figures" offer advice that is just plain wrong. US readers: EU law is different from US law in that it is generally approachable and readable. While in the US it is difficult to even know which laws apply to you without the help of an experienced lawyer (because of case/precedent law), in the EU this is much easier. So don't be af…
I've read it and I'm still confused. Without caselaw and a lawyer how am I to determine which data processing are considered "legitimate interest" in Article 6? Recital 47 is supposed to clarify this, but it's still pretty vague and it says legitimate interests may provide a legal basis for processing. May? How do I know if they do or do not?
Re: 2018 reform of EU data protection rules
#109PSA: Please make sure you're not relying on HN comments for your understanding of the GDPR if you're the one responsible in your organization. I need to get back to all the panicked questions CS has forwarded to me (the DPO equivalent for my company), but please understand that there's a lot of misunderstanding in every HN thread on this topic.
Heh, I'd say that it's even worse than "misunderstanding". Besides honest misunderstanding, there's so much FUD being spread by people on HN who are afraid that their greedy data manipulation plan for a startup has been completely foiled... So much FUD that you definitely feel sometimes that the comments are straight out of http://n-gate.com/ Caricaturizing (a bit): "HN1: The GDPR takes away our freedom to make tons…
Re: 2018 reform of EU data protection rules
#110Enforcement factsheet: https://ec.europa.eu/commission/sites/beta-political/files/d... Pretty clearly primarily enforced by national regulatory agencies, who are the only ones who can apply fines . It mentions citizens taking companies to court, but https://ec.europa.eu/commission/sites/beta-political/files/d... says that's for monetary damages, not for fines. This is unchanged from previous laws. Can people stop fre…
And: > Your company is service provider based outside the EU. It provides services to customers outside the EU. Its clients can use its services when they travel to other countries, including within the EU. Provided your company doesn't specifically target its services at individuals in the EU, it is not subject to the rules of the GDPR. (emphasis mine)
I would guess most people selling something on the internet have at least some small percentage of customers in the EU.