Live data from Hacker News

2018 reform of EU data protection rules

ec.europa.eu

111–120 of 150 posts

Re: 2018 reform of EU data protection rules

#111
So .... github, sourceforce, bitbucket. When someone asks to delete their data do all their commits have to be deleted or edited to remove their name from the commit logs? How about changelog if the project has one? Comments from source? I'm guessing you'll say "no, because they agreed to open source their data" but how is that any different from agreeing to so-and-so's terms of service?

In the same manor what happens to wikis and wikipedia when a user wants to delete their data?

If the data was copied by another user does that data become their's to keep or does that need to be deleted too? Example: Jill sends Karen Jill's address via Facebook. Jill want's all of Jill's data deleted from Facebook. Does Jill's address she sent to Karen have to be deleted? Pictures? Pre-internet that data would be on a piece of paper in Karen's possession. Now it's less clear as it's really in Facebook's possession and Karen just has access to the data on Facebook's servers. As Karen I'd be upset if what I considered my data (my copy of Karen's address) to be deleted but is that clear in the GDPR?

Re: 2018 reform of EU data protection rules

#112
post #104

Earlier quoted context omitted.

They're only way more profitable right now because they exist. I guess if you want to sell something the EU has pretty much banned, basing your business inside the EU won't work.

How can an alternative be more profitable? Targeted ads allow to TARGET someone. That means that instead of wasting views on someone that won't be interested (and thus, be a waste of money) you use it on people that will care. For sure if you have 5$ of budget per sale, if it takes 1000 views to get a sale or 1 views, you won't pay the same for views in both situation depending on the efficiency of the ad.

Life isn't only about profit.

Advertising often can have a very negative and destructive effect, we shouldn't base our societies around how best to sell stuff.

Web companies and web advertising companies have been building huge, secret dossiers on all their visitors, unexpectedly selling, sharing and distributing sensitive data about their customers with totally unrelated third parties.

Now society's saying, that's not cool. Here are the new rules. We'll heavily punish your companies if you do it again.

Re: 2018 reform of EU data protection rules

#113
post #10
post #2

An important one to note as it's applicable to all businesses whose customers include EU residents because it addresses the collection and processing of their personal data locally and internationally.

I do not believe that is correct. Right now, for example, if you are a US business with no offices or employees in EU jurisdiction then there is little the EU can do if you are not GDPR compliant - regardless of whether you deal with EU traffic or not. The EU might wish their laws were global, but that doesn’t make it so. #notalawyer

[deleted]

Re: 2018 reform of EU data protection rules

#114
post #10
post #2

An important one to note as it's applicable to all businesses whose customers include EU residents because it addresses the collection and processing of their personal data locally and internationally.

I do not believe that is correct. Right now, for example, if you are a US business with no offices or employees in EU jurisdiction then there is little the EU can do if you are not GDPR compliant - regardless of whether you deal with EU traffic or not. The EU might wish their laws were global, but that doesn’t make it so. #notalawyer

The regulation asserts the scope of data protection as global; it's applicable to all foreign companies processing data of EU residents, whether the companies are based in the EU or not.

It will be interesting to see how the mechanisms of enforcement play out but I imagine there are plans for direct and indirect implementation in situations that warrant the harshest options (ban on processing and/or monetary fine). E.g. getting cooperation from payment or logistics processors to stop processing EU sales of a offending foreign company. A halt on sales or delivery of goods to such a large region could be crippling for a company.

Re: 2018 reform of EU data protection rules

#115

Earlier quoted context omitted.

And: > Your company is service provider based outside the EU. It provides services to customers outside the EU. Its clients can use its services when they travel to other countries, including within the EU. Provided your company doesn't specifically target its services at individuals in the EU, it is not subject to the rules of the GDPR. (emphasis mine)

Correct me if I'm wrong, but I think that changes as soon as you have one paying customer located in the EU (even if you were not specifically targeting the EU). I would guess most people selling something on the internet have at least some small percentage of customers in the EU.

GDPR applicability for those outside the EU still requires at least some active targeting of users (website in EU languages, currencies) in the EU rather than EU users passively coming to your website to purchase.

If I make a purchase from a bespoke banjo shop in Guatemala whose site is in Spanish and prices in Cuetzals that I've stumbled across on the internet then they don't go into scope of GDPR.

Re: 2018 reform of EU data protection rules

#116
post #86

Earlier quoted context omitted.

And it's not just HN. I've listened to at least three podcasts by now where "well-known figures" offer advice that is just plain wrong. US readers: EU law is different from US law in that it is generally approachable and readable. While in the US it is difficult to even know which laws apply to you without the help of an experienced lawyer (because of case/precedent law), in the EU this is much easier. So don't be af…

The fact that there's so much confusion suggests that it is not that easy to understand. I've read it and I'm still confused. Without caselaw and a lawyer how am I to determine which data processing are considered "legitimate interest" in Article 6? Recital 47 is supposed to clarify this, but it's still pretty vague and it says legitimate interests may provide a legal basis for processing. May? How do I know if they…

Legitimate interests and consent should be the two processing grounds that you rely on as a last resort here.

As to your point, legitimate interests requires a balancing act between your interests and others' interests and so is by its nature going to be uncertain.

If you are looking to rely on legitimate interests, you should look to document your interests that you think are being served through the processing, and also check to see if any other processing bases may be more suitable to achieve your objective. The aim is to at least have a defensible position behind your use of legitimate interests.

Here an example of Facebook listing out their legitimate interests in making use of data:

https://www.facebook.com/about/privacy/legal_bases

Re: 2018 reform of EU data protection rules

#117
post #11

Earlier quoted context omitted.

I honestly can't wait to ask my local retailer what data they have on me based on their loyalty cards. So far they were exempt from data disclosure laws because they were not an IT company.

I always lose my loyalty card from time to time (it doesn't have any loyalty advantages you just have to have it to get the discounts) and ask for a new one. I wonder if they were able to link them back together

I always just use the phone number approach -- give them 867-5309 an when they ask "yeah, I'm Jenny". Works every time. Last time at the Walgreens they tried to give me a $5 discount but I had to know the zip code assigned to the account so was like "nah, next time."

Re: 2018 reform of EU data protection rules

#118
post #48

Earlier quoted context omitted.

I think in the current situation, having strong privacy for all users will be a feature you can bring to the market, especially for US users it can be a big plus since the US doesn't have any comparable privacy law.

How do you communicate this? Most people don't care.

There are already companies like ProtonMail that sell the privacy laws of Switzerland as a pro and they seem to do alright.

Re: 2018 reform of EU data protection rules

#119
post #86

Earlier quoted context omitted.

And it's not just HN. I've listened to at least three podcasts by now where "well-known figures" offer advice that is just plain wrong. US readers: EU law is different from US law in that it is generally approachable and readable. While in the US it is difficult to even know which laws apply to you without the help of an experienced lawyer (because of case/precedent law), in the EU this is much easier. So don't be af…

The fact that there's so much confusion suggests that it is not that easy to understand. I've read it and I'm still confused. Without caselaw and a lawyer how am I to determine which data processing are considered "legitimate interest" in Article 6? Recital 47 is supposed to clarify this, but it's still pretty vague and it says legitimate interests may provide a legal basis for processing. May? How do I know if they…

It's disappointing to see comments like the parent being downvoted. Evidently the situation still isn't clear, because if it were then we wouldn't be having GDPR-related discussions on HN almost daily now where people who are currently dealing with these issues professionally have reached very different conclusions and/or received very different advice.

I think the biggest problem for many of us is still the uncertainty. For all the mountains of "guidance" now being generated by the EU and the national regulators at five to midnight, there is still very little advice provided that is unambiguous and actionable when it comes to some of the most fundamental questions. What does or doesn't constitute a legitimate interest basis for processing data? When is such an interest is or isn't overridden by the subject's own interests? How long would be considered a reasonable period to retain data for common purposes? Answers like "as short a time as possible, but that might be 20 years" simply aren't useful.

Re: 2018 reform of EU data protection rules

#120
post #97

Earlier quoted context omitted.

Also: https://ec.europa.eu/info/law/law-topic/data-protection/refo... The authority must ensure that fines imposed in each individual case are effective, proportionate and dissuasive. It will take into account a number of factors such as the nature, gravity and duration of the infringement, its intentional or negligent character, any action taken to mitigate the damage suffered by individuals, the degree of cooperati…

There's a problem when "The authority must ensure...", i.e. when there's a lot of discretion granted to "The authority", that's because "The authority" will use any law available to try to silence or harm dangerous individuals when there are "hidden" political reason to do so. Example: http://www.bbc.com/news/world-europe-39973864 An antidote to this potential abuse is to make laws scarce and highly specific and make…

And a will the EU favor European companies over foreign companies in enforcement practices?
Post reply on HN