Earlier quoted context omitted.
This might be a bit of a weird question, but how do you remember which information needs to be deleted when you're at the point where you need to use backups?
You would keep a list of unique identifiers (opaque) that were deleted and filter data out prior to rewriting/restoring it. It’s cumbersome but not impossible.
GDPR for lazy people: Block all European users with Cloudflare Workers
691–700 of 1001 posts
Re: GDPR for lazy people: Block all European users with Cloudflare Workers
#692Earlier quoted context omitted.
How do you handle developer computers with possible client data on them, even semi-anonymized? Or when communicating issues on the live server, you might transfer client information to other stake holders to debug issue. Are you tracking that communication. Where does the communication data reside, perhaps on a server outside of the EU? There is a lot of complications that arise if you think about the second order/th…
I don’t know GDPR inside and out, but I have worked at places (not military) where I could be held criminally liable for misuse or negligent disclosure of PII. The answer to “How do you handle...” is that you get your shit together. Separation of duties, build and configuration standards, no customer data on random laptops. When I was in high school, I worked at a sandwich/coffee shop. The precious commodity in that…
The word choice almost presumes the conclusion, that data privacy rules are obvious, and cheap, and akin to just washing hands after using the toilet.
Every regulation has costs and benefits. I also would love to have better worldwide privacy at no or little cost, but the fact that people are blocking the EU shows that some companies just don't see this to be the case. And they're voting with their feet.
EU citizens should accept the fact that if they support the law, they will further data privacy protections, which are good, and they will face the music if some innovation leaves or whatever compliance costs may come with it.
Re: GDPR for lazy people: Block all European users with Cloudflare Workers
#693Re: GDPR for lazy people: Block all European users with Cloudflare Workers
#694Earlier quoted context omitted.
1. when you open a restaurant nobody cares you're a collage student. You have to have all the checks and permits to serve people food. It's not because somebody hates small businesses, it's because the right not to be poisoned is more important than the right to do business hassle-free. Why should internet be different? 2. Fuck your souvereignty. Seriously. USA has no problem violating secrecy of correspondency world…
Equivocating mishandling user data on a project that some kid in a dorm made for fun, which collects maybe an email address. With putting someone in the hospital with food poisoning is beyond a dishonest comparison.
When corporations like Equifax or Cambridge Analytica have engaged in identity theft to the tune of basically half the continent of North America, you want to repeal one of the few laws fighting against it with an argument about kids in dorm rooms? It's basically the tech equivalent of "won't somebody think of the children?"
Re: GDPR for lazy people: Block all European users with Cloudflare Workers
#695Earlier quoted context omitted.
Here's a thought: regulation like this is, along with the heavy-handed ideology that lead to it, is the reason why the EU is still lagging regarding technical innovation. I think this attitude is the primary reason Silicon Valley took hold in the USA and that the EU has nothing comparable. If the EU wants to legislate itself out of the future they're more than welcome to do so -- and I applaud every site who makes th…
Is it? Visit Germany sometime. Drive through the countryside. Most parts of the US look like a hollowed out shell by comparison.
Re: GDPR for lazy people: Block all European users with Cloudflare Workers
#696Earlier quoted context omitted.
It's reassuring to hear that the GDPR is not meant to target little startups and projects but I would like it a lot better if it said that in the actual law, rather than just trusting all current and future regulators to treat me kindly. If it's only meant to be used against big companies or extreme offenders, why doesn't it say so? It seems like the spirit of the law and the language of the law are not aligned and i…
"but I would like it a lot better if it said that in the actual law" Have you read the bloody law! http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX... This is legislation designed to protect not only me (as an individual) but you as well (as a probable foreigner) from me!
Out of an 88 page law, 1% of an auxiliary middle of the law is carved out for small companies.
I'm not sure that counts as differential application for small companies. In the US at least, large portions of entire key burdensome laws don't apply for employers below size 50, 10, 5, etc. This does not seem to be the case here.
Does anyone know whether an official impact study on innovation was even done before its passage?
Re: GDPR for lazy people: Block all European users with Cloudflare Workers
#697Earlier quoted context omitted.
GDPR just says that if you are keeping data, you have to have a good reason for it. If you have to retain certain data for eg tax purposes, then that sounds like a good reason to me.
It has 99 articles arranged over 11 chapters. It does not "just [say] that if you are keeping data, you have to have a good reason for it".
Re: GDPR for lazy people: Block all European users with Cloudflare Workers
#698Earlier quoted context omitted.
Upthread we have the claim that "most early-stage startups use the... best practice of 'delete=1'," pretending to delete user data while actually retaining it. So, the exact opposite of the rule.
Yes, and many things will remain that way with GDPR because of necessity (ie: old invoices and transactions will continue to have your details). Most startups are doing their best to be good stewards of data, and they didn't need big global regulation to force them. But do let me know when GDPR actually does anything to deal with ISPs, credit unions, medical companies, and plenty of other institutions that have breac…
If that were true we wouldn't be seeing daily threads here (like this one) that effectively amount to "I don't want to follow the law/protect the data I collect" for months now.
Re: GDPR for lazy people: Block all European users with Cloudflare Workers
#699Earlier quoted context omitted.
It hinders nothing. It ensures that what you're with user data doing is truly voluntary and that your users really are 'willing and eager" about it beyond you pinky-swearing you'll be good with what you're given. Be annoyed all you want, the only people whining about the GDPR are those showing their true colors when it comes to user privacy and agency. If you're complaining that it hinders you from using user data as…
To be clear, I'm annoyed as a user too. Partly by the discrepancy between the claim that I now have control over my data, but can't actually use it since the small independently run services can't accept my data even if I wanted them to, because that acceptance comes with a set of requirements that are prohibitive, and which I, the user, would not want in this instance. However, judging by some of the other responses…
You're not allowed to sell yourself to slavers, even if you want to. Slavers can't exist at all. It's understood that if they did, the slavers would exploit your "freedom" to create a world where, in reality, the circumstances leave you no alternative except to "freely choose" to be a slave.
Re: GDPR for lazy people: Block all European users with Cloudflare Workers
#700Earlier quoted context omitted.
> I do not give a damn whether you're soft-deleting or hard-deleting my IP address and my user account You don't give a damn; neither do those computer illiterate people who use the same email address and password for everything, and one leak of some shitty inconsequential website may obliterate their entire online presence.
I'm not sure how the GDPR fixes anything, since those people aren't going to be capable of finding the hidden "delete account" button five pages into a big tech company's byzantine privacy settings.