Live data from Hacker News

2018 reform of EU data protection rules

ec.europa.eu

141–150 of 150 posts

Re: 2018 reform of EU data protection rules

#141
post #140

Earlier quoted context omitted.

They're responsible for whatever user monitoring their third-party ecommerce platform does, right? All the ones I've seen process and retain user data. And maybe their web analytics, A/B testing, email newsletter tracking, etc. If your point is that static brochureware sites that don't target EU members at all and don't do anything interesting on the web probably don't have much to worry about... then I agree, but I…

Heh, apologies for not being more insightful! I was simply rebutting your point over the GDPR applying once you’ve made a few sales to customers in the EU which is not the case on those facts alone. Obviously each case should be dealt with on its own facts to assess the application of GDPR. In the example you give, GDPR may well apply. Some companies may be worried, others may see it as an opportunity. I know lots of…

Assuming you actually do something with your user's data -- and virtually every online business does -- then I think it is true that GDPR comes into play as soon as you have a single EU user. How you market the service is no longer relevant.

I wish it were as easy as saying the law doesn't apply if your business doesn't target EU business. Unfortunately I don't actually think it's possible to escape GDPR. Even refusing to serve all EU IP Addresses wouldn't be completely effective.

I'm sure lots of companies view this as an opportunity. Especially the big ones with experience with compliance issues, in-house counsel, etc. It's going to be tougher on the small guy.

Re: 2018 reform of EU data protection rules

#142

Earlier quoted context omitted.

Where would "non-targeted" ads even come from? How can you use an ad network or even run a standard ad server in a way that doesn't share at least the reader's IP Address? Mom and pop publishers who don't have the resources or ability to staff their own ad sales team are going to be in trouble. The big players who can work around this obstacle are going to be fine. I'm not happy about this.

IP address is only personally identifable info if it is coupled with other info that links it to a real person. Storing an IP address by itself and sharing it is not, by itself PII

like, have you read the guideline?

Re: 2018 reform of EU data protection rules

#143

This is a great resource because it is from the EU, provides clear examples, cites the actual legislation and Article 29 Working Party Guidelines (which is the group that is tasked with preparing official opinions on GDPR). I think that if you want to really comprehend something, you should go to the primary source. The GDPR legislation is far more approachable than it seems (as an official 261 page PDF). When the pr…

I respectfully disagree. This is a terrible resource, which frequently says things that are either mostly vacuous or just plain wrong. For example, here's their page on the right to erasure: https://ec.europa.eu/info/law/law-topic/data-protection/refo... Its opening paragraph reads as if data subjects have an automatic right to have their data deleted unless one of the three exceptions applies. In fact, Article 17 of…

Well, you're clearly thinking deeply about this and you seem to care. Which is great. I've been digging in deep on this the last few months so I have some thoughts. Respectfully (srsly), I think you might be misinterpreting the legislation (this resource is provides more concrete examples of how you should interpret it).

For example, Article 17(1) lays out the MANY grounds upon which a Data Subject can request erasure. If ONE of the mentioned criteria is met including the very broad Right to Object (Article 21) then it must be erased. 17(2) states you must fwd this request on to other online orgs. 17(3) provides the exceptions for which a Controller can object to the erasure.

It is important to note that the spirit of GDPR is one where Data Subjects rights (to their data, to object) are the default. Sort of like innocent until proven guilty. This is a big shift for most companies who would contend that they own the data & data exhaust from use of their application.

As for compliance demonstration... yes, this is still a mess. My only suggestion there is that if you're working with software companies, try to study what the leaders are doing and take some inspiration. https://www.enterpriseready.io/gdpr/preparing-for-gdpr/

Happy to hear your thoughts. Genuinely interested in other people's perspectives on this.

Re: 2018 reform of EU data protection rules

#144

So .... github, sourceforce, bitbucket. When someone asks to delete their data do all their commits have to be deleted or edited to remove their name from the commit logs? How about changelog if the project has one? Comments from source? I'm guessing you'll say "no, because they agreed to open source their data" but how is that any different from agreeing to so-and-so's terms of service? In the same manor what happen…

Let's stop coming up with stupid, stupid examples where you have spend more time thinking about how to troll than thinking how the GDPR applies. (Hint: The right to erasure is not absolute, and applies to personal data.)

And what is personal data? this problem exists even without the GDPR, my question is does the GDPR make it law in the EU. In Google Docs if Jill shares a document with Karen and then Jill deletes her account Karen will lose access to the Jill's document. That situation doesn't map to the real world where sharing a document meant Jill sending Karen a physical copy. Personally I consider it a bug given it doesn't fit expectations from the real world. If a document shows up in Karen's files it's Karen's copy of that document. Karen shouldn't have to track which docs are actual copies and which are still considered Jill's.

In any case given it's possible to delete Jill's data from Google is Google required to delete the document from Karen's account even if Karen has made a copy? Where is this covered? It's not really Karen's copy, both are Google's copy. It's on their servers.

This is not trolling. This is trying to understand the GDPR.

Re: 2018 reform of EU data protection rules

#145

Earlier quoted context omitted.

It's really hard to tell. Between the people who haven't read the GDPR, the people who are trolling, the people who are willfully misrepresenting the GDPR because they politically oppose it, the people who don't understand privacy or nuance, and the people who are trying to interpret the GDPR into an American legal system, there's so much low-quality discussion. Meanwhile, I don't know of any Europeans who don't supp…

Meanwhile, I don't know of any Europeans who don't support it (on an individual level) or who finds it confusing. Hi, I'm a European who doesn't support it and who does find it confusing. To be more precise, while I'm generally in favour of better privacy protections in law, I don't support this poorly implemented attempt, because I think it will have all sorts of unintended consequences that may not be in individual…

> Hi, I'm a European [...] (the UK)

Not for much longer :D But seriously, the British government and the various police forces don't have a great track record with regards to privacy (e.g. Investigatory Powers Act), so it's no wonder the ICO is underfunded and has had a very limited mandate.

> Given that things like access history/event logs are important for things like protecting ourselves against potential legal actions, disputed charges and the like, there is no possible way to give an intelligent answer to that.

Audit logs are an interesting example for sure. But that's a bit vague. Maybe somebody somewhere will sue us! Sounds like you need a lawyer regardless, and a competent lawyer should be able to identify a lawful basis with such strong documentation.

The GDPR is maybe a bit heavy-handed compared to a gradual approach, because EU countries have previously had a hard time getting companies to comply with their data protection laws.

Re: 2018 reform of EU data protection rules

#146

Earlier quoted context omitted.

They explicitly contradict you. https://ec.europa.eu/info/law/law-topic/data-protection/refo... The law applies to... 2. a company established outside the EU offering goods/services (paid or for free) or monitoring the behaviour of individuals in the EU. Do you have any evidence? You're doing business with EU citizens. You allow them to connect to your site. Wouldn't this operate similarly to how extradition by the U…

It does not matter what EU thinks. What matters if what can EU do and the answer is nothing unless your company operates in Europe > Wouldn't this operate similarly to how extradition by the US of foreign hackers work? It would not.

[deleted]

Re: 2018 reform of EU data protection rules

#147

Earlier quoted context omitted.

I respectfully disagree. This is a terrible resource, which frequently says things that are either mostly vacuous or just plain wrong. For example, here's their page on the right to erasure: https://ec.europa.eu/info/law/law-topic/data-protection/refo... Its opening paragraph reads as if data subjects have an automatic right to have their data deleted unless one of the three exceptions applies. In fact, Article 17 of…

Well, you're clearly thinking deeply about this and you seem to care. Which is great. I've been digging in deep on this the last few months so I have some thoughts. Respectfully (srsly), I think you might be misinterpreting the legislation (this resource is provides more concrete examples of how you should interpret it). For example, Article 17(1) lays out the MANY grounds upon which a Data Subject can request erasur…

For example, Article 17(1) lays out the MANY grounds upon which a Data Subject can request erasure. If ONE of the mentioned criteria is met including the very broad Right to Object (Article 21) then it must be erased.

Yes, but crucially, if the data is still relevant and you're processing it on a proper basis, the data subject doesn't necessarily have a right to have it erased.

If your only legal basis for processing is consent, subjects get most of the rights under the GDPR automatically and you have very little choice about complying. One of the big changes in the new regime is that consent can be withdrawn retrospectively.

If your basis is legitimate interests, things are more complicated. Subject rights are stronger in this situation than with some of the other legal bases, because they can object to processing. However, the right to object is itself subject to balancing tests that aren't clearly defined, except in the specific case of direct marketing.

For the stronger bases, such as performance of a contract or compliance with legal obligations, subject rights are still quite limited even under the GDPR. For example, under EU VAT rules, we are required by law to keep evidence of where our customers are located for quite a long time, and customers can't require us to delete that evidence prematurely.

There are some other important details to be considered, for example if you're processing data about children, but that seems to be the basic situation.

Re: 2018 reform of EU data protection rules

#148

Earlier quoted context omitted.

Meanwhile, I don't know of any Europeans who don't support it (on an individual level) or who finds it confusing. Hi, I'm a European who doesn't support it and who does find it confusing. To be more precise, while I'm generally in favour of better privacy protections in law, I don't support this poorly implemented attempt, because I think it will have all sorts of unintended consequences that may not be in individual…

> Hi, I'm a European [...] (the UK) Not for much longer :D But seriously, the British government and the various police forces don't have a great track record with regards to privacy (e.g. Investigatory Powers Act), so it's no wonder the ICO is underfunded and has had a very limited mandate. > Given that things like access history/event logs are important for things like protecting ourselves against potential legal a…

the British government and the various police forces don't have a great track record with regards to privacy (e.g. Investigatory Powers Act)

I'd be the first to agree, and I'm generally in favour of stronger privacy protections in law, particularly around government behaviour. But of course governments get a pass on many things that are otherwise restricted anyway, because they just have to whisper the magic words (usually something like "national security") and the carefully written exemptions in almost every piece of privacy and data protection legislation ever written are activated.

Audit logs are an interesting example for sure. But that's a bit vague. Maybe somebody somewhere will sue us!

That's the problem, though, isn't it? These needs are vague and you can't predict when they will arise. Nevertheless, they do happen. In fact, the example I mentioned before happened just this week.

Sounds like you need a lawyer regardless, and a competent lawyer should be able to identify a lawful basis with such strong documentation.

In my experience, having spoken now to several different people who are consulting on the GDPR including some who are lawyers, even they don't know the answers here. They have no crystal ball, and the language is so open to interpretation, and the regulators are so late at providing any guidance, and what guidance they have provided is often so poor that no-one really knows how this is going to play out yet. This of course creates uncertainty that is damaging in itself.

Re: 2018 reform of EU data protection rules

#149

Earlier quoted context omitted.

Let's stop coming up with stupid, stupid examples where you have spend more time thinking about how to troll than thinking how the GDPR applies. (Hint: The right to erasure is not absolute, and applies to personal data.)

And what is personal data? this problem exists even without the GDPR, my question is does the GDPR make it law in the EU. In Google Docs if Jill shares a document with Karen and then Jill deletes her account Karen will lose access to the Jill's document. That situation doesn't map to the real world where sharing a document meant Jill sending Karen a physical copy. Personally I consider it a bug given it doesn't fit e…

What, just like you don't "own" software, you buy a license which can be revoked at any time? The digital world doesn't map to physical concepts any more. Even before the GDPR, Google has always been able to shutter your account for various ToS violations, and you better hope you had backed it up.

Re: 2018 reform of EU data protection rules

#150

Earlier quoted context omitted.

And what is personal data? this problem exists even without the GDPR, my question is does the GDPR make it law in the EU. In Google Docs if Jill shares a document with Karen and then Jill deletes her account Karen will lose access to the Jill's document. That situation doesn't map to the real world where sharing a document meant Jill sending Karen a physical copy. Personally I consider it a bug given it doesn't fit e…

What, just like you don't "own" software, you buy a license which can be revoked at any time? The digital world doesn't map to physical concepts any more. Even before the GDPR, Google has always been able to shutter your account for various ToS violations, and you better hope you had backed it up.

What happens at google is irrelevant except to demonstrate the issue. The question is whether or not the GDRP REQUIRES that Jill's copies she sent to Karen get deleted from Karen's account.
Post reply on HN