Live data from Hacker News

Shutting Down Forum (GDPR)

discourse.drone.io

151–160 of 534 posts

Re: Shutting Down Forum (GDPR)

#151
post #118

I"m not really a fan of the GDPR. I don't think it really protects privacy. I think it just uses the power of the EU, a fairly big and strong organization, to intimidate the rest of the world to comply with laws that it really shouldn't have legal jurisdiction to enforce globally. I think this is a scary precedent to set that the biggest bully on the block can de facto enforce such standards because the rest of the w…

> If you want none of your personal info on the web, I have a suggestion: Don't participate in forums, social media, etc. There are tons of companies processing my personal data that are not web companies. GDPR isn't about "data being on the web", it's about all handling of personal data.

If you walk into a store and buy something, does the owner not have a right to record relevant personal information as it pertains to the sale, such as when buying a car? This idea that those vendors ought to be required to delete records seems backwards — you aren’t required to interact with entities that do things you don’t like — unless it’s the government, no escaping that.

Public records are potentially more harmful than anything Facebook has. For example, I just shipped a 20 foot container of household goods to the US from France — that manifest, including my personal information is public record — I have to explicitly send a letter and request privacy for that shipment — and then remember to renew that request each year or else details of my entire shipment, including my address and contact information are available publicly. Thanks government. I can’t simply use another shipping company — it’s a government rule. When GDPR applies to governments, then I might become a fan, but as it is now, I am being “protected” from my Facebook likes or web history but what protections do I have from governments who traffic in my information. There is zero reason my shipment manifest needs to be known beyond Customs or the shipping company moving the goods, yet, here we are. Facebook never committed mass murder — but governments certainly have. Google Analytics data doesn’t have a realistic chance of causing harm — but someone with my address and a manifest of a shipment of expensive stuff results in a potential for real harm — that stuff is literally public record with absolutely no controls over who can buy that information.

Re: Shutting Down Forum (GDPR)

#152
post #53

Earlier quoted context omitted.

> If there's a risk that someone could sue you over something, Which bit of GDPR introduces that risk?

Maybe sue isn't the correct term, but you are talking about potentially a 20 million dollar fine. I'm being told that the EU would never pursue that with a small business and they'd just tell you what you need to fix. That also sounds weird to me as an American. I'm not saying it isn't true, just that it's not the way I'm used to thinking about laws.

Even in the worst case scenario you have the option of going out of business and filing for bankrupcy if you are incorporated in the EU and do get hit by a 20M fine. The EU can certainly try to take that amount from the company, but if it's a Ltd. or Gmbh. or equivalent its liability is limited by its shares.

Or you can incorporate outside of the EU (Guernsey or soon enough the UK perhaps?) and ignore the GDPR. At which point we'll just wait and see if the EU has any teeth outside its jurisdiction and how it will enforce this law.

Re: Shutting Down Forum (GDPR)

#153

Could/should probably ignore GPDR requests if your business operations are entirely US based, whether or not anyone from the EU uses your site. US national sovereignty doesn't disappear because the EU says jump. We are not bound by the laws of governments other than our own. You can probably ignore them anyway if you aren't a big company. With millions of these troll letters going around (and probably getting ignored…

If you make money from EU users and are US based you need to be GDPR compliant or they will target you through payment processors and ad networks. If you don't make money from EU users and don't want to be GDPR compliant you should probably just shut them off if you ever want to operate in the EU in the future

So you admit that GDPR is really just a trade barrier.

Re: Shutting Down Forum (GDPR)

#154

Earlier quoted context omitted.

This already happens. Russia sent notices to GitHub about certain documents that were hosted there. China and Saudi Arabia just straight up block things they don’t like.

Yea, but this emboldens them because they can now point to EU and say that this is what normal countries do, long arm[0] people around. [0] https://en.wikipedia.org/wiki/Long-arm_jurisdiction

Or US with DMCA requests.

Re: Shutting Down Forum (GDPR)

#155
post #86

Earlier quoted context omitted.

About 3 minutes. "Here's the privacy policy. Here's the data export page."

Haha data export page, what even is that? Let me just go to my SQL DB, redis, glacier backups, and Kafka logs and just click the data export button. It will only take 3 minutes.

Maybe you could create some sort or reusable digital tool that could be used to aggregate all the data for any given user? Perhaps it be could be called a "script" or "program"?

Re: Shutting Down Forum (GDPR)

#156
post #99

Earlier quoted context omitted.

European law tends to talk about the maximum available penalty under the worst possible situation. It then gives a list of factors to be taken into account. I'm not sure why that's a bad thing. Look at the US COPPA, with potentially $41,000 per violation. Why isn't this more scary for American website operators? https://www.ftc.gov/tips-advice/business-center/guidance/com... > A court can hold operators who violate t…

COPPA is frightening to web operators, at least in the abstract. The majority of web services online at least make a cursory effort to either ban users under the age of 13 from accessing the site or force them to give parental consent. Technically speaking, if you're under 13 you're not really supposed to be on sites like Twitter. The equivalent reaction for GDPR would be if everyone either started making half-hearte…

> ..started making half-hearted efforts to block European users (which isn't what EU wants..

Are we sure about that? GDPR seems like a gift to European startups who don’t like American competition. BlaBlah car in France got huge, incidentally right around the time the anti-Uber hysteria in France reaches a peak. The sale of Daily Motion to Yahoo was blocked by the French government under ridiculous national economic interest grounds. Europe loves tariffs and trade barriers and they have a history of “protecting” the public from competition. Try shipping spare parts for a child’s stroller to France — I was taxed at 50% — the tax even applying to the shipping fee, not just the parts. My dad made the mistake of sending kids clothes to my kids with the tags still on them — $100 worth of clothes cost me €65 in duties. When I ship small amounts of stuff to the US, I literally have never had to pay a tax. The EU loves protectionism. Farmers literally set fires and throw rocks when Spanish wine crosses into France and the authorities don’t prosecute a single person. Now that EU countries have a bunch of lotteries tickets with American tech companies, the governments are likely foaming at the mouth with excitement over fining American companies. And, sadly, many people in Europe actually think this is about privacy.

Re: Shutting Down Forum (GDPR)

#157
post #96

The GDPR seems to me to be just another example of nontechnical authorities trying to regulate what they don't understand. Why don't more technical people become politicians, or at least form lobbying groups or think tanks?

The response to the GDPR seems to me to be a bunch of people who fundamentally misunderstand how law works, especially in Europe, and who have a pathological relationship to regulators because their own legal system is fucked beyond all recognition. GDPR requires you to only gather the data you need; only keep it for as long as you need it; tell people what you're doing with it; and allow them to correct it if it's w…

... and document every instance of processing, as well as the legal basis for processing for each use of each piece of data, and how you decided that legal basis (and if you used "legitimate interest," you need to do a LIA -- the template I use is several pages before you enter the information). Then you have to negotiate different DPA terms with a dozen clients whose privacy lawyers told them they each need a different term because we privacy professionals still have no idea what parts of this law mean. Oh, and then you have to handhold customers who think they know more about privacy law than you do because they read a 500-word rundown of the GDPR, because if you don't nicely convince them they're wrong, they'll make a complaint.

There's plenty more, but you get the idea. Anyone who says implementing this law is simple isn't implementing this law in a business of normal size and complication.

Re: Shutting Down Forum (GDPR)

#158

Earlier quoted context omitted.

The law has been proposed by the European Commission who is just nominated not elected.

The European Commission's members are sent there by the national governments. Elect another parliament/government if you don't like who yours did sent.

That’s like saying if you don’t like a police officer then elect a different city council. Parliament members don’t campaign on who they’ll nominate to the EU commission. Brexit can’t come fast enough.

Re: Shutting Down Forum (GDPR)

#159
post #54

Earlier quoted context omitted.

Just act in good faith and GDPR will not bite. Do you have $20million to make that gamble?

Nobody will fine an open-source project that amount of money. The goal of GDPR is not to bankrupt anybody but to nudge them into compliance. If you aren't maliciously handling user data, you are not a target of high fines.

Then why does the law not have this an an exemption?

Re: Shutting Down Forum (GDPR)

#160
post #118

Earlier quoted context omitted.

> If you want none of your personal info on the web, I have a suggestion: Don't participate in forums, social media, etc. There are tons of companies processing my personal data that are not web companies. GDPR isn't about "data being on the web", it's about all handling of personal data.

If you walk into a store and buy something, does the owner not have a right to record relevant personal information as it pertains to the sale, such as when buying a car? This idea that those vendors ought to be required to delete records seems backwards — you aren’t required to interact with entities that do things you don’t like — unless it’s the government, no escaping that. Public records are potentially more har…

The owner of the store does have the right to record the sales transaction data. But that was never under dispute even with GDPR. GDPR specifically says that you do not have the right to be forgotten in the information is important for legal compliance (e.g. tax records), free speech, and a couple of other things.

https://ico.org.uk/for-organisations/guide-to-the-general-da... See “when does [it] not apply?”

GDPR already applies to governments. What makes you think it is not?

https://www2.deloitte.com/nl/nl/pages/risk/articles/gdpr-in-...

> Starting May 25th 2018, all organisations, including those in the public sector, need to comply with the GDPR.

Government agencies have been working their asses off to become GDPR compliant. If you have a problem with the way your shipping info is handled, file a complaint against that government agency at the French data protection authority.

Please stop the FUD. The right to be forgotten has never been absolute and applies to both companies and government.

Post reply on HN