Live data from Hacker News

Google Emerges as Early Winner from Europe’s New Data Privacy Law

wsj.com

61–70 of 94 posts

Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law

#62
post #39

Earlier quoted context omitted.

> I'm speaking to the issue of you or I creating an MVP with a few months of dedicated hard work. How much extra time has to be spent on putting in place a process for data deletion? None. Do not target the EU initially, start in the US market with your MVP. It's by far the most liberal major market to do an MVP in, in all regards. It's the world's largest economy and easily accessible; plus you essentially get Canad…

That'd be fine if the GDPR were constrained to business done inside the EU, but it purports to exercise authority over any entity which asks for any information from any EU citizen, inside or outside of its borders. Enforcement and jurisdiction have yet to be tested yet, of course, but it isn't as simple as "don't set up shop in the EU".

It doesn't matter what the EU purports, that's nothing more than a comical fantasy on their part. I live in the US, my business operates in the US, I operate by US law.

It also doesn't matter what China purports I should do with their citizen data, or South Africa, or Australia, or Brazil: their wishes don't overrule the supremacy of US law inside the US. If China wants me to delete everything on my service about Tiananmen Square, or an anti-China activist, guess what, that's not going to happen for the exact same reason. I'm also not subject to the UK government's enforced media blackout on the Tommy Robinson arrest: they too can piss off.

If a EU citizen signs up with my US based service, their data will be governed by US law.

It is that simple. It will remain that simple. The US isn't going to cede its sovereignty to the EU: it's drastically more powerful than the EU in every regard. There is no scenario where the US lays back and allows the EU to legislate how the domestic US economy operates in such large ways.

The only likely outcome is that the US comes up with its own new privacy rules in the next few years, which will be different - more lenient - than GDPR. If you want to operate in the two markets, you'll have to comply with each approach accordingly.

Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law

#63
post #12

Earlier quoted context omitted.

I don't think "startups" should be able to get away with just doing a "deleted=1" with my personal data, or to not know where my data is ending up, just because they are "startups".

There's a large distance between not knowing where your data ends up/using it badly and being actually GDPR-compliant, which in many businesses requires a massive administrative burden.

There isn't, especially for small companies. Also, it starts with recognizing that it's not their data, it's user's data.

Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law

#64
post #41

The perverse effect of these consent buttons is that people who configured their browsers to flush all cookies and session data on closing the session get harassed much more as websites do not remember their choice, even if they are the ones actually least likely to be tracked (save for browser fingerprinting).

Nail on head!

It's complete irony. I am seriously clicking through these ginormous modals like there is no tomorrow when i have to do research on many websites.

"Free surfing" or should we say old school internet surfing has become a chore now because of these idiotic modals.

I am sure people will flee to walled gardens pretty quickly if they have to constantly make extra clicks to access stuff.

Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law

#65
post #49

Earlier quoted context omitted.

The sum total requirement for reporting taxes on a hobby project in the US is filling out a single 1099-MISC at the end of the year, during a process that you'll already be doing anyway. It's not an onerous burden which introduces significant friction to the process of bringing a new idea to fruition. I'm not saying "hobbyists shouldn't have to comply with the law", I'm saying "the law is disproportionately punitive…

If, and only if, you don't know what you're doing with your data. Most cases can be covered with a bit of forethought and some documentation. "Hey, I need to be able to query and delete data" is not a huge cognitive overhead when creating a MVP.

It's not just querying and deleting data, though.

You have to be able to demonstrate audit trails of consent, including what the user consented to and when. You have to be able to demonstrate audit trails proving deletion requests. You have to have audit trails of who has ever accessed this data. You have to have a means to exclude pieces of your dataset from aggregate statistics on demand. Also, your audit trails can't contain PII because then your audit trails are in violation of the deletion requests, so you have to have mechanisms of proving that you processed deletion requests without actually identifying the data processed. You're also now obligated to respond to data inquiries in perpetuity, even to people for whom you have no data. Article 32 appears to impose a requirement for encryption at rest, high availability, disaster recovery, and regular penetration testing - all good things, to be sure, but completely impractical for the small hobbyist. Your "querying and deleting" is, by the letter of the law, now required to be a full-blown production-ready architecture with a business's worth of documentation.

And all because you wanted an email address to keep your login form from getting spammed?

I realize that in practicality, this is unlikely to ever be leveraged in any significant scope against most hobbyists, but the law is merciless and it is foolish to assume that you won't be caught in its crosshairs just because you weren't its intended target.

Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law

#66

Earlier quoted context omitted.

There's a large distance between not knowing where your data ends up/using it badly and being actually GDPR-compliant, which in many businesses requires a massive administrative burden.

There isn't, especially for small companies. Also, it starts with recognizing that it's not their data, it's user's data.

Do most small companies have a CIPP/E or privacy lawyer (or someone who has equivalent training/experience) on staff? We know statistically that not only don't they, but they can't, because there aren't enough of them out there. And if you don't, you'd better have an insanely simple business, because otherwise you're not going to come close to compliance.

Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law

#67
post #60
post #3

GDPR is yet another moat for established companies. It may take them some time to adapt their data models and engineer systems for data deletion, but once they have done so, it becomes something every startup will have to implement in order to compete. I'm not saying GDPR isn't good for privacy (we need it); it just makes competition harder.

> yet another moat for established companies What if GDPR is what pushes distributed computing into the mainstream? If GDPR makes it even harder for small fry to compete with the giants, then the small fry should change the rules. Zero centralized servers, zero PII, no EULAs, no legaleze, only open-source P2P. Megacorps can be GDPR-compliant with buildings full of lawyers, and the rest will be GDPR-irrelevant with no…

>zero PII, no EULAs, no legaleze, only open-source P2P

how that should work exactly? I mean, even if platform is P2P, you still have user id, you still have user interests, et cetera.

The only thing changed bc of P2P is that it gets much more complicated, or even impossible, to delete your account/data.

Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law

#68
Both in how companies are complying and in the public discourse, I’m seeing a jumbling of ‘consent’ and ‘notice’ that doesn’t align with my understanding of the intent and reading of the law. Under the transparency principle (Art. 5) and disclosure obligations (Arts 13 and 14), there are a variety of things that must be disclosed to a data subject at time of collection. See https://gdpr-info.eu/ for easy access to the law’s text. That’s what privacy polices (increasingly called privacy notices) are generally used for. Many companies are trying to either make you click something to prove they’ve notified you or add language to the notices saying “by using this site, you consent to this privacy policy”, which is a form of ‘consent’ they are deciding to collect themselves. Separately, a controller is supposed to have a legal basis for processing personal data (Art. 6). Consent of the data subject is only one of six legal bases. Legitimate interests of the controller is the other common basis for a business and is expected to be relied up on increasingly since the GDPR makes collecting valid consent harder and it has the downside that it must be tracked and can be withdrawn (which also must be tracked). Consent as a basis is not allowed to be buried in a privacy policy. It must be called out separately with a separate consent for each purpose the data will be used for on an opt-in basis. The policies and these consents all are supposed to be presented in as simple and plain English as possible and it’s encouraged to use layered notices/policies to convey quick summaries with an ability to drill down. To add to the complexity, email marketing is governed by the ePrivacy Directive (responsible for the cookie banners) and requires consent. Each country has its own enactment of ePrivacy so compliance is very complex. Also, under the GDPR, a data subject has an absolute right to object to direct marketing regardless of the basis being relied upon. Much of this flurry of email privacy policy updates and/or consents to marketing are conflating ePrivacy and the GDPR. What I see right now is a bit of a mess as companies try to figure out what compliance looks like and balance full disclosure (transparency) with simple, easy, plain English disclosure.

Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law

#69

Earlier quoted context omitted.

There's a large distance between not knowing where your data ends up/using it badly and being actually GDPR-compliant, which in many businesses requires a massive administrative burden.

If it requires a massive administrative burden, that company has collected or is in the business of collecting a lot of personal data. In which case, it's good that there's a burden, since they are holding a lot of sensitive data and should be held accountable for what they do with it, and how they allow it to be used.

1. One can collect "a lot" of personal data without any of it being sensitive.

2. The amount of personal data and the administrative burden are sometimes correlated, but often aren't. Collecting name and email from a few people in eighteen different ways creates a much, much larger administrative load than collecting name, email, and ten other items of information in a single way.

3. One can use all that personal data well and not violate the rights of data subjects without being remotely GDPR-compliant.

4. Most of the administrative burden does little to nothing for how well data subjects' data is used.

Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law

#70
post #39

Earlier quoted context omitted.

That'd be fine if the GDPR were constrained to business done inside the EU, but it purports to exercise authority over any entity which asks for any information from any EU citizen, inside or outside of its borders. Enforcement and jurisdiction have yet to be tested yet, of course, but it isn't as simple as "don't set up shop in the EU".

It doesn't matter what the EU purports, that's nothing more than a comical fantasy on their part. I live in the US, my business operates in the US, I operate by US law. It also doesn't matter what China purports I should do with their citizen data, or South Africa, or Australia, or Brazil: their wishes don't overrule the supremacy of US law inside the US. If China wants me to delete everything on my service about Tia…

I'd like to think that you're right, but I also don't want to be the guy that has to spend several hundred thousand dollars to defend that thesis in court.
Post reply on HN