Live data from Hacker News

2018 reform of EU data protection rules

ec.europa.eu

121–130 of 150 posts

Re: 2018 reform of EU data protection rules

#121

Earlier quoted context omitted.

How would you anonymise an IPv4 address? Hashing isn't enough, because that would be easy to brute force. And you can't create a table mapping IPs to anonymized-IPs, because then you are still storing them.

Google Analytics drops the last octet IIRC. Hashing isn't anonymizing because the hash can later be used to re-identify a user. (See https://ec.europa.eu/info/law/law-topic/data-protection/refo... )

Since there are legitimate use-cases where you need to be able to somehow identify requests coming from the same IP (protection against DDoS), you would be allowed to do it, given that you take reasonable steps to protect the user (such as deleting the logs after a few days when there's no suspicious activity).

And then hashing the IP addresses would be such a reasonable step, too, since it removes location information from the stored data.

Re: 2018 reform of EU data protection rules

#122

So .... github, sourceforce, bitbucket. When someone asks to delete their data do all their commits have to be deleted or edited to remove their name from the commit logs? How about changelog if the project has one? Comments from source? I'm guessing you'll say "no, because they agreed to open source their data" but how is that any different from agreeing to so-and-so's terms of service? In the same manor what happen…

Let's stop coming up with stupid, stupid examples where you have spend more time thinking about how to troll than thinking how the GDPR applies.

(Hint: The right to erasure is not absolute, and applies to personal data.)

Re: 2018 reform of EU data protection rules

#123
post #60
post #2

An important one to note as it's applicable to all businesses whose customers include EU residents because it addresses the collection and processing of their personal data locally and internationally.

This is not true. Just read the regulation. It's pretty clear that unless you're located in the EU or you're pursuing EU residents then the GDPR does not apply to you. Logically, it should be clear that the GDPR cannot apply to any business who an EU citizen stumbles upon and decides to buy something. The entire motivation of the GDPR is to prevent surveillance of EU residents with respect to their actions in the Uni…

It is true. Article 3.2 reads:

This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to:

- the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or

- the monitoring of their behaviour as far as their behaviour takes place within the Union.

Re: 2018 reform of EU data protection rules

#124
post #115

Earlier quoted context omitted.

Correct me if I'm wrong, but I think that changes as soon as you have one paying customer located in the EU (even if you were not specifically targeting the EU). I would guess most people selling something on the internet have at least some small percentage of customers in the EU.

GDPR applicability for those outside the EU still requires at least some active targeting of users (website in EU languages, currencies) in the EU rather than EU users passively coming to your website to purchase. If I make a purchase from a bespoke banjo shop in Guatemala whose site is in Spanish and prices in Cuetzals that I've stumbled across on the internet then they don't go into scope of GDPR.

Article 3 says it applies when -EITHER- of the following is true:

(a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or

(b) the monitoring of their behaviour as far as their behaviour takes place within the Union.

Re: 2018 reform of EU data protection rules

#125
post #103

Earlier quoted context omitted.

Removing the last 3 digits would often uniquely identify a larger company or a city and if you only have 1 user from that city/company, those records would be easy to connect. Maybe Google is hoping the EU will accept that balance of concerns, but it doesn't sound like it realises the spirit of the law.

If your reference to 'you' means someone running a site who only has possession of a reduced IP address, then how would connection work? Or are you saying that if I went to an ISP with the reduced IP address, they could disclose details of the person, if they only had 1 account within the range of IP addresses that the restricted IP address covered? This doesn't seem particularly likely to me? I thought ISPs hold a b…

Nothing to do with the isp - but if you have users so you know who they are and then you also track people by ip network, you are now storing tracking logs that can be identified with a specific user.

For example if hacker news did this and one of your comments contained your city or company, now they can connect your account to an anonymized analytics user.

Re: 2018 reform of EU data protection rules

#126

This is a great resource because it is from the EU, provides clear examples, cites the actual legislation and Article 29 Working Party Guidelines (which is the group that is tasked with preparing official opinions on GDPR). I think that if you want to really comprehend something, you should go to the primary source. The GDPR legislation is far more approachable than it seems (as an official 261 page PDF). When the pr…

I respectfully disagree. This is a terrible resource, which frequently says things that are either mostly vacuous or just plain wrong.

For example, here's their page on the right to erasure:

https://ec.europa.eu/info/law/law-topic/data-protection/refo...

Its opening paragraph reads as if data subjects have an automatic right to have their data deleted unless one of the three exceptions applies. In fact, Article 17 of the GDPR itself grants that right only under a list of specific circumstances, and the exceptions are just that, which is an entirely different situation that will lead to the opposite decision on whether data must be erased in many normal situations. Even the list of exceptions shown isn't complete.

For another example, here's their page on demonstrating compliance:

https://ec.europa.eu/info/law/law-topic/data-protection/refo...

There is literally nothing on that page that would help any business I'm dealing with to demonstrate compliance, unless you count the references to the primary sources at the end. There are a couple of ideas about codes of conduct or certifications that contain no substantial details, and even the vague hints about other things you might have to do don't go into any detail about who does or doesn't, leaving the entire page almost entirely content-free unless you happen to be in an industry where the kind of scheme they mention exists.

This sort of "guidance" is everything that is wrong with how the GDPR is being handled. It is verbose, ambiguous, sometimes seriously misleading, and almost entirely non-actionable. I'm actually worse off than I was before I read it, because I know nothing useful now that I didn't know before, I would have been misled by several of the pages such as the one I mentioned above if I hadn't already known better, and that's still half an hour of my life wasted.

Re: 2018 reform of EU data protection rules

#127

Earlier quoted context omitted.

The fact that there's so much confusion suggests that it is not that easy to understand. I've read it and I'm still confused. Without caselaw and a lawyer how am I to determine which data processing are considered "legitimate interest" in Article 6? Recital 47 is supposed to clarify this, but it's still pretty vague and it says legitimate interests may provide a legal basis for processing. May? How do I know if they…

It's disappointing to see comments like the parent being downvoted. Evidently the situation still isn't clear, because if it were then we wouldn't be having GDPR-related discussions on HN almost daily now where people who are currently dealing with these issues professionally have reached very different conclusions and/or received very different advice. I think the biggest problem for many of us is still the uncertai…

It's really hard to tell. Between the people who haven't read the GDPR, the people who are trolling, the people who are willfully misrepresenting the GDPR because they politically oppose it, the people who don't understand privacy or nuance, and the people who are trying to interpret the GDPR into an American legal system, there's so much low-quality discussion.

Meanwhile, I don't know of any Europeans who don't support it (on an individual level) or who finds it confusing. The hardest part seems to be putting processes in place for the right to erasure, but then we've had similar provisions in EU countries for a while, so it's not a big deal.

As for "reasonable period to retain data", unless required by law, you won't get into trouble for deleting data more quickly. So what's the minimum period you absolutely need that data/those logs/those backups for?

There's no one-size-fits-all approach, so the law isn't written like that. We just assume most people will be decent/"reasonable" in implementing it, and if not, there's the sanctions.

[0[ https://ico.org.uk/for-organisations/guide-to-the-general-da...

Re: 2018 reform of EU data protection rules

#128

Earlier quoted context omitted.

It's disappointing to see comments like the parent being downvoted. Evidently the situation still isn't clear, because if it were then we wouldn't be having GDPR-related discussions on HN almost daily now where people who are currently dealing with these issues professionally have reached very different conclusions and/or received very different advice. I think the biggest problem for many of us is still the uncertai…

It's really hard to tell. Between the people who haven't read the GDPR, the people who are trolling, the people who are willfully misrepresenting the GDPR because they politically oppose it, the people who don't understand privacy or nuance, and the people who are trying to interpret the GDPR into an American legal system, there's so much low-quality discussion. Meanwhile, I don't know of any Europeans who don't supp…

Meanwhile, I don't know of any Europeans who don't support it (on an individual level) or who finds it confusing.

Hi, I'm a European who doesn't support it and who does find it confusing.

To be more precise, while I'm generally in favour of better privacy protections in law, I don't support this poorly implemented attempt, because I think it will have all sorts of unintended consequences that may not be in individuals' best interests, while also imposing a disproportionate burden on controllers and processors who weren't abusing that data for unsavoury purposes anyway, particularly smaller organisations.

And maybe "confusing" isn't quite the right word, but in my view it's far too ambiguous in its treatment of some of the most fundamental issues to provide a good platform for future data protection. Much of the official guidance is confusing, often to the point of being misleading and counterproductive, however.

we've had similar provisions in EU countries for a while, so it's not a big deal.

All regulation is a big deal if you're running a microbusiness and don't have dedicated staff to deal with it. In any case, there are several new or significantly extended rights introduced by the GDPR that certainly weren't there before in my country (the UK).

So what's the minimum period you absolutely need that data/those logs/those backups for?

Given that things like access history/event logs are important for things like protecting ourselves against potential legal actions, disputed charges and the like, there is no possible way to give an intelligent answer to that. I can, however, state as fact that we have had to rely on detailed log records from several years ago when threatened with actual action by someone who was clearly trying to take advantage of the situation and hadn't expected us to still have evidence that undermined their claims, so any claim that we can just cycle these things out after a few days is demonstrably false. Given that we're not doing anything particularly unusual either legally or in processing data for everyday business purposes, I have to assume we are far from alone in having these experiences and the concerns they raise.

There's no one-size-fits-all approach, so the law isn't written like that.

While that may be true, it is entirely useless to someone well-intentioned and acting in good faith who is trying to work out what they actually have to do to comply with the new regulations.

Re: 2018 reform of EU data protection rules

#129
post #124
post #115

Earlier quoted context omitted.

GDPR applicability for those outside the EU still requires at least some active targeting of users (website in EU languages, currencies) in the EU rather than EU users passively coming to your website to purchase. If I make a purchase from a bespoke banjo shop in Guatemala whose site is in Spanish and prices in Cuetzals that I've stumbled across on the internet then they don't go into scope of GDPR.

Article 3 says it applies when -EITHER- of the following is true: (a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or (b) the monitoring of their behaviour as far as their behaviour takes place within the Union.

Yes, that's right. Are you implying that our notional Guatemalan banjo seller is monitoring the behaviour of EU based subjects? I confess I was working on the basis that out the two potential options, Art 3(2)(b) would be inapplicable here, but you may know more than me about their activities!

Re: 2018 reform of EU data protection rules

#130

Earlier quoted context omitted.

It's disappointing to see comments like the parent being downvoted. Evidently the situation still isn't clear, because if it were then we wouldn't be having GDPR-related discussions on HN almost daily now where people who are currently dealing with these issues professionally have reached very different conclusions and/or received very different advice. I think the biggest problem for many of us is still the uncertai…

It's really hard to tell. Between the people who haven't read the GDPR, the people who are trolling, the people who are willfully misrepresenting the GDPR because they politically oppose it, the people who don't understand privacy or nuance, and the people who are trying to interpret the GDPR into an American legal system, there's so much low-quality discussion. Meanwhile, I don't know of any Europeans who don't supp…

I think very few people here are trolling. I'm certainly not. And I think it's unkind to attribute malice to those who are confused or merely disagree.

> We just assume most people will be decent/"reasonable" in implementing it, and if not, there's the sanctions.

My definition of "reasonable" isn't the same as that of European regulators. I know this because I don't consider IP Address to be PII. Luckily for me on this particular point the GDPR is explicit in saying that it is. If I were left to define PII myself though, I could well have opened myself to regulatory action as IP Addresses were logged and shared incidentally with third parties in many places.

I think this style of writing laws gives way, way too much power to regulators. Particularly for companies with no physical EU presence and thus no way to vote or have any say in how the regulators work.

I think very few online businesses will be fully 100% compliant with every provision of the GDPR and all it's current and future interpretations. So we need to just hope and trust that all the regulators in all the Union countries won't punish anyone who doesn't really deserve it. That's not a good situation.

> So what's the minimum period you absolutely need that data/those logs/those backups for?

There is no answer to this question. Strictly speaking I don't need any backups or logs. I've also, rarely, encountered subtle data corruption bugs in the wild where having backups that go back months was critical and the more the better.

Post reply on HN