Live data from Hacker News

Ask HN: Could EU residents comment on how the GDPR has improved their privacy?

news.ycombinator.com

31–40 of 78 posts

Re: Ask HN: Could EU residents comment on how the GDPR has improved their privacy?

#31
I've used the new laws twice now to close online accounts with companies that were uncooperative or too 'clingy' (looking at you, OVH and Microsoft). Much easier to send a registered letter than waiting on hold or searching for an online option that was deliberately made hard to find, or which may not exist at all.

I have also used it to stop unwanted postal ads from local companies. I get to find out how they obtained my info, and also stop some junk mail.

For the sibling comments mentioning the GDPR popups / cookie notices, why not add a blocklist for these to your adblocker? At this point adblockers should be considered basic security software, like a firewall or antivirus. These lists exist are are pretty comprehensive.

As an American living in Europe I think it's a great law and I wish there was something comparable to protect my friends and family stateside. And as someone who administers a fair amount of business and client data, I do not find the law inconvenient to comply with. I am very pro-privacy and protective of user data, and I didn't have to make any major adjustments.

Re: Ask HN: Could EU residents comment on how the GDPR has improved their privacy?

#32
post #26

I don't know about privacy, but it certainly increased the amount of popups I have to click through daily. Thanks, wise European bureaucrats.

Blame the content providers who are unnecessarily tracking you, and not the legislators that force them to now tell you.

Do you really think people on HN are scared of cookies? Ha. Save it for the CNN comments pages ok.

edit: If you're not worried about the cookies then can you take the requirement for state mandated popups on any site that uses cookies out of the GDPR, thanks.

edit 2: (due to being throttled for wrongthink)

According to the GDPR website to comply you must "Receive users’ consent before you use any cookies except strictly necessary cookies." How do you suggest websites get users consent other than popups? I'm sure everyone who is sicking of clicking through them and everyone who is sick of implementing them would love to hear about it. Why don't you "Show HN"?

Re: Ask HN: Could EU residents comment on how the GDPR has improved their privacy?

#33
In terms of what a company has to do, not that much changed since GDPR's predecessor. The difference between the previous law from the 90s and GDPR is mainly publicity (privacy wasn't as big a topic in the 90s) and higher fines, so what I notice as an EU resident is that more companies implement it. (Also companies abroad, but I can't say that e.g. Google's update impacted me beyond annoying banners: they still say "you consent to us doing anything we like" and that is probably legal.)

The previous law was optional to implement for member states but I lived in a member state (the Netherlands) that did (as "Wet Bescherming Persoonsgegevens") and I think most other states did as well. Any company that wants to do business in the Netherlands had to comply with that law already (just like you can't come here to do business that is illegal for any other reason).

The main features as I see them are that companies have to obtain consent or have a valid reason for processing personal data, and you have a right to view your data. That was the case and is still the case. I've done data access requests prior and post GDPR and the responses are identical.

A number of details changed, but if you complied with the previous law and you're not a personal data broker, then you have to do very little to comply with GDPR. To give an example, consent now has to be "freely" and unambiguously given, whereas before it just had to be unambiguously given, which means that an employer can't ask you for consent due to the power relation and it's popularly interpreted to also mean that you can't bundle it ("consent or don't get the service") because then it's not "freely" given.

Re: Ask HN: Could EU residents comment on how the GDPR has improved their privacy?

#34
I was able to get my account and data deleted from a crypto exchange with relatively little fuss.

Had I not been protected by GDPR I would have had to submit documents to prove my identity, none of which was even required to operate the account in the first place.

Re: Ask HN: Could EU residents comment on how the GDPR has improved their privacy?

#35

Earlier quoted context omitted.

Unfortunately, yes. I haven't knowingly opted-in to anything. This may be a problem with the whole "click here to accept all these cookies" bullcrap that is on every site. I dont think this apparent benefit of the GDPR has worked - at all. However, in the organisations I have worked with professionally, GDPR is absolutely working - user data collection, storage and security is now a leading conversation - whereas it…

Accept cookies has nothing to do with GDPR. GDPR has to do that if you provide your phone/mail to some shop or other service they can only use it to contact you with information directly related to their business, like processing your order etc. They can not send you marketing stuff unless you explicitly consented and must remove you from lists if you ask. Even delete your account if you ask (not the data tho).

GDPR added the bit where you can opt out of cookie usage on a case by case basis (by use case or by data processor). American companies usually don't implement that part in a correct or legal manner (they have no incentive for doing so; they're only pretending "your privacy is so very, very important to them" for PR reasons). European companies doing it wrong are on shaky ground, since it's a matter of time until some regulator somewhere (which one depends on their country) slaps them with massive fines.

On data removal: https://ec.europa.eu/info/law/law-topic/data-protection/refo...

Re: Ask HN: Could EU residents comment on how the GDPR has improved their privacy?

#37
post #19

Popups everywhere. Insane bureaucracy, even at the doctor. And when it matters, it's just being ignored. Most (medium-sized) companies haven't even realized there is a new law.

I haven't noticed any "insane bureaucracy" at the doctor, but there's a new box to tick in the signup forms

> And when it matters, it's just being ignored.

Where is that? Though you're welcome to point those out to your country regulator.

> Most (medium-sized) companies haven't even realized there is a new law.

Actually they have, I was surprised at getting emails from medium sized, non-online business about it

Re: Ask HN: Could EU residents comment on how the GDPR has improved their privacy?

#38
This has improved privacy awareness, curbed data hoarding and reduces tracking across the board. It also made people aware of which companies don't have their IT in correct order. (i.e. those that outright ban EU traffic, or don't prompt to ask if they can hoard your data)

Re: Ask HN: Could EU residents comment on how the GDPR has improved their privacy?

#39
post #19

Popups everywhere. Insane bureaucracy, even at the doctor. And when it matters, it's just being ignored. Most (medium-sized) companies haven't even realized there is a new law.

Popup situation is really bad

There should be a standard implementation of these popups so that I don't have to do it for each new website on each new browser again and again.

Re: Ask HN: Could EU residents comment on how the GDPR has improved their privacy?

#40
I pretty much prefer to have a popup that I have to "accept" prior to the website I visit can "legally" start storing identifiable information about me, it allows me to just close the webpage if it's not something essential I'm visiting. Like 90% of the links on the web, lets say more or less, are not really worth my data, sort of just a "let me check" curiosity, that 99% of the time, after you would finish the article/post wtv, you would go "that was another turd". This doesn't mean it's completely effective or not at all but it's at least some legal backing/precedent.

I still hope we'll be able at some point to come up with a more refined protocol than http (or better sandboxing of the browser/device), where you could selectively reject loading JS resources and where resources would need to explicitly say what they were gathering, where pixel tracking would need to be announced (and only after your consent would those resources run/load). Totally ok with the site not loading either if you didn't gave the permissions. Probably never going to happen, but that would be a true handshake, "I want to check this out", RE: "Sure, we want your location, track your navigation across the website and we'll sell this as part of a dataset, including your IP, so that someone else then can buy several different datasets and create a proper picture of your activity", "Sorry, thanks, not interested". (and yes, it would need to be written in a way that's understandable, not 5 pages of crap). The same applied to mobile phones/computers/apps.

Or better yet, a browser/device API, where you (the developer) would need to declare all resources you wanted to access (DEVICE_IP_ADDRESS, DEVICE_LOCATION, MOUSE_POSITION etc) this would compile all of them into legible manifest that you could read before it being un-sandboxed and allowed to run. Any attempt to read such information from the browser/device where one of those permissions weren't granted would return null (might be the best argument for the existence of null).

Post reply on HN