Live data from Hacker News

Google Emerges as Early Winner from Europe’s New Data Privacy Law

wsj.com

81–90 of 94 posts

Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law

#81

Earlier quoted context omitted.

If it requires a massive administrative burden, that company has collected or is in the business of collecting a lot of personal data. In which case, it's good that there's a burden, since they are holding a lot of sensitive data and should be held accountable for what they do with it, and how they allow it to be used.

1. One can collect "a lot" of personal data without any of it being sensitive. 2. The amount of personal data and the administrative burden are sometimes correlated, but often aren't. Collecting name and email from a few people in eighteen different ways creates a much, much larger administrative load than collecting name, email, and ten other items of information in a single way. 3. One can use all that personal dat…

One can collect "a lot" of personal data without any of it being sensitive.

I don't think this is the case at all. Essentially all personal data is sensitive.

The amount of personal data and the administrative burden are sometimes correlated, but often aren't. Collecting name and email from a few people in eighteen different ways creates a much, much larger administrative load than collecting name, email, and ten other items of information in a single way.

That's true, but also seems entirely reasonable. If you are collecting data in eighteen different ways, that means there are eighteen times as many ways you can fail to adequately audit or secure it.

One can use all that personal data well and not violate the rights of data subjects without being remotely GDPR-compliant.

Probably technically true, but in practice? Regulators are more concerned about compliance than anything else. Are there likely scenarios in which data is collected and processed in a responsible manner, but technical GDPR compliance is a huge burden?

Most of the administrative burden does little to nothing for how well data subjects' data is used.

Why would this be the case? Most of the administrative requirements appear to be entirely justified methods to ensure that you have understood and evaluated the methods of compliance.

Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law

#82

Earlier quoted context omitted.

There isn't, especially for small companies. Also, it starts with recognizing that it's not their data, it's user's data.

Do most small companies have a CIPP/E or privacy lawyer (or someone who has equivalent training/experience) on staff? We know statistically that not only don't they, but they can't , because there aren't enough of them out there. And if you don't, you'd better have an insanely simple business, because otherwise you're not going to come close to compliance.

You can _obviously_ come into compliance without an on-staff privacy lawyer.

Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law

#83
post #26

Earlier quoted context omitted.

The only difference is that dumping toxic waste in rivers does actual, concrete harm. Targeted advertising? The worst I’ve heard about it is that it makes some people feel a little icky. I suppose that’s a concrete harm in a sense but it seems a much less serious one, at least to me.

> The worst I’ve heard about it is that it makes some people feel a little icky. Yeah sure, all that privacy, who needs it anyway? /s

I’m sorry but this is not really a substantive objection to what I said. Yes, people have a vague preference for privacy. I never disputed that. No, failing to respect that preference has not caused material, externally visible harm.

Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law

#84

Earlier quoted context omitted.

1. One can collect "a lot" of personal data without any of it being sensitive. 2. The amount of personal data and the administrative burden are sometimes correlated, but often aren't. Collecting name and email from a few people in eighteen different ways creates a much, much larger administrative load than collecting name, email, and ten other items of information in a single way. 3. One can use all that personal dat…

One can collect "a lot" of personal data without any of it being sensitive. I don't think this is the case at all. Essentially all personal data is sensitive. The amount of personal data and the administrative burden are sometimes correlated, but often aren't. Collecting name and email from a few people in eighteen different ways creates a much, much larger administrative load than collecting name, email, and ten oth…

> I don't think this is the case at all. Essentially all personal data is sensitive.

Noooooo, not according to this or any other privacy law. Under the GDPR, it's "data consisting of racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, biometric data, data concerning health or data concerning a natural person's sex life or sexual orientation."

> Are there likely scenarios in which data is collected and processed in a responsible manner, but technical GDPR compliance is a huge burden?

Yes. My company, and most companies of other privacy professionals I've talked to.

> Why would this be the case? Most of the administrative requirements appear to be entirely justified methods to ensure that you have understood and evaluated the methods of compliance.

If you think that any cost is justified to ensure that something that ought to be done is actually being done, sure. By any analysis of costs and benefits, I think you might come to a different conclusion, but that would require some kind of real analysis of costs and benefits. I haven't seen that from anyone who is both (a) a supporter of the law and (b) has actually spent time implementing it in a real, involved business that deals with personal data (and I mean actually implementing it, and not the absurdly simple version many HN commenters seem to be doing that doesn't include massive amounts of documentation).

Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law

#85

Earlier quoted context omitted.

Do most small companies have a CIPP/E or privacy lawyer (or someone who has equivalent training/experience) on staff? We know statistically that not only don't they, but they can't , because there aren't enough of them out there. And if you don't, you'd better have an insanely simple business, because otherwise you're not going to come close to compliance.

You can _obviously_ come into compliance without an on-staff privacy lawyer.

I know a lot of companies that think they have, and most of them are wrong. Some are deeply wrong.

Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law

#86
post #65

Earlier quoted context omitted.

If, and only if, you don't know what you're doing with your data. Most cases can be covered with a bit of forethought and some documentation. "Hey, I need to be able to query and delete data" is not a huge cognitive overhead when creating a MVP.

It's not just querying and deleting data, though. You have to be able to demonstrate audit trails of consent, including what the user consented to and when. You have to be able to demonstrate audit trails proving deletion requests. You have to have audit trails of who has ever accessed this data. You have to have a means to exclude pieces of your dataset from aggregate statistics on demand. Also, your audit trails ca…

> And all because you wanted an email address to keep your login form from getting spammed?

No, all this because companies were selling your email address to spammers.

Also, your reading of the law seems at odds with most other readings I've seen. I'm sure it will come down to a lawyer - but I'm also sure that hobby programmer who take reasonable steps won't ever be in the crosshairs of the EU.

Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law

#87

Earlier quoted context omitted.

I hate to break it to you, but the idea behind the GDPR is gaining traction outside the Europe. Fighting this trend is only going to hurt more in the long run.

> the idea behind the GDPR is gaining traction outside the Europe I hope it does. Europe, however, has a unique penchant for unnecessary bureaucracy. Nobody is complaining about GDPR’s requirements. It’s the ancillary administration which is destructive.

What enforces compliance if there is no administration - the administration is the teeth of the compliance.

Companies have had years in which they were receiving warnings and recommendations for best practices - they ignored them. This is the piper coming with the bill.

Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law

#88
post #74

Earlier quoted context omitted.

> The worst I’ve heard about it is that it makes some people feel a little icky. The worst I've heard of was the abuse of millions of people's data by Cambridge Analytics to mess with an election, but maybe that's just a little icky too?

Your usage of "abuse" is offensive to people that really experienced abuse.

Yeah right, because words always just have one meaning and one context.

Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law

#89
post #59

Earlier quoted context omitted.

> Just asking for an email that will literally be used for nothing but to send a registration confirmation - you know, to sign up users, the same way we've been doing forever - puts you in its compliance crosshairs. You're now legally liable for a whole raft of additional compliance measures that probably necessitate paying a lawyer a decent chunk of change to make sure you're above board with. You have to tell the u…

Yeah, that's article 5. There are 98 additional articles to the law, many of which impose additional administrative and technical requirements on your product. Just saying "I'm using your email for signups" doesn't make you compliant. If it did then I doubt anyone would have a problem with it.

If there are 98 additional articles applying to e-maol signups, why did the poster go to such great lengths to introduce so many other factors which had nothing to do with e-mail signups?

Other than to try and make the regulations seem more baroque than they are.

Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law

#90
post #60

Earlier quoted context omitted.

> yet another moat for established companies What if GDPR is what pushes distributed computing into the mainstream? If GDPR makes it even harder for small fry to compete with the giants, then the small fry should change the rules. Zero centralized servers, zero PII, no EULAs, no legaleze, only open-source P2P. Megacorps can be GDPR-compliant with buildings full of lawyers, and the rest will be GDPR-irrelevant with no…

>zero PII, no EULAs, no legaleze, only open-source P2P how that should work exactly? I mean, even if platform is P2P, you still have user id, you still have user interests, et cetera. The only thing changed bc of P2P is that it gets much more complicated, or even impossible, to delete your account/data.

> you still have user id, you still have user interests

No _you_ don't.

Peers on the network may have this but there's no entity subject to GDPR.

So if GDPR tilts the playing field in favor of the megacorps, perhaps it also encourages anonymity and distributed networks.

Post reply on HN