Live data from Hacker News

Ask HN: Could EU residents comment on how the GDPR has improved their privacy?

news.ycombinator.com

51–60 of 78 posts

Re: Ask HN: Could EU residents comment on how the GDPR has improved their privacy?

#51
post #33

In terms of what a company has to do, not that much changed since GDPR's predecessor. The difference between the previous law from the 90s and GDPR is mainly publicity (privacy wasn't as big a topic in the 90s) and higher fines, so what I notice as an EU resident is that more companies implement it. (Also companies abroad, but I can't say that e.g. Google's update impacted me beyond annoying banners: they still say "…

But it did change for everyone else that didn't have those laws. Also, the impact of a brach is much bigger now.

> it did change for everyone else

OP was asking for EU residents to comment on how it impacted them. This is how it impacted me. If someone else is very happy with GDPR because their country didn't implement the previous law (DPD), they should comment separately.

Edit: actually, all EU member states implemented the DPD: https://en.wikipedia.org/wiki/Data_Protection_Directive#Impl...

So this is actually representative for everyone else.

> Also, the impact of a [breach] is much bigger now

Indeed, as I mentioned, the fines are higher, and that's the only change in that regard.

Note that the requirement to report data breaches to the authorities is not a GDPR thing. The Netherlands introduced a separate law for that prior to GDPR.

And the reason you can be fined for a breach is not because you had a breach. It's not a crime to become the victim of criminal activity, so that's also not new with GDPR. The reason for it resulting in a fine is that it often highlights inadequate security of personal data, which was also illegal under the previous law.

Re: Ask HN: Could EU residents comment on how the GDPR has improved their privacy?

#53
post #32

Earlier quoted context omitted.

Blame the content providers who are unnecessarily tracking you, and not the legislators that force them to now tell you.

Do you really think people on HN are scared of cookies? Ha. Save it for the CNN comments pages ok. edit: If you're not worried about the cookies then can you take the requirement for state mandated popups on any site that uses cookies out of the GDPR, thanks. edit 2: (due to being throttled for wrongthink) According to the GDPR website to comply you must "Receive users’ consent before you use any cookies except stric…

It's not the cookies we're concerned about.

Re: Ask HN: Could EU residents comment on how the GDPR has improved their privacy?

#54
post #20

Earlier quoted context omitted.

The cookie pop ups were a thing before, I guess being able to opt-out is a neat feature but there are certainly companies who do not comply when you choose to opt-out. (Looking at you Verizon, yes I know it’s you behind “oath”.)

Any opt-out popups anyway aren't caused by GDPR anyway, as consent is 'GDPR-kosher' only if it's explicitly opt-in. If I take no action, accept the default conditions and don't opt out of anything, then that must be interpreted as me not granting permission to anything - there are a bunch of data use-cases that you're allowed to do without my consent, so you don't need the popups for that, but otherwise no informed e…

That's how it should work, but in practice most popups are opt out. I've seen only one type of cookie popup that comes with default opt in, and even that one has a very proeminent 'opt in to all and save' button and a slightly harder to find 'just save' button that will actually allow the opt out to stay.

Re: Ask HN: Could EU residents comment on how the GDPR has improved their privacy?

#55
It's fantastic.

A lot of sites throw up a modal that just disappears when you say no. And I've verified that in most instances this completely kills all telemetry.

I was involved working at a SaaS that provided first party personalisation at the time GDPR was introduced and heard a lot of stories about clients just dropping pointless and long term data.

I have family in the school system that called panicking that this was a disaster... then a few months later admitted it meant that they actual handle their data well and no longer accidently leak personal info (financial, medical, behaviour, attainment) to other families, kids, teachers, or third party companies. Oh, and their emergency fire list is now kept up to date.

I've used the powers of the GDPR to eliminate some low level harrassment of my grandfather.

Google, Facebook, and the Yahoo auth group are still diddling with data they shouldn't, but on the whole it is a much much better world.

Re: Ask HN: Could EU residents comment on how the GDPR has improved their privacy?

#56
My personal stages of gdpr experience:

Stage one: these cookie consent popups are empowering. I'm glad the people won.

Stage two: I am getting a bit sick of having to understand custom consent forms on every site.

Stage three: what have we done, cookie consent has made the internet suck even more!

Stage four: I wonder what all this privacy stuff is really about (goes and reads about it).

Stage five: The internet is a strip mall crossed with a red light district run by the mob - we are doomed.

Stage six: This is something the government will be bad at for quite some time, and I actually have the power to take control of my personal privacy and freedom with minimal effort (relative to say overthrowing a tyrannical government).

Re: Ask HN: Could EU residents comment on how the GDPR has improved their privacy?

#57
post #32

Earlier quoted context omitted.

Blame the content providers who are unnecessarily tracking you, and not the legislators that force them to now tell you.

Do you really think people on HN are scared of cookies? Ha. Save it for the CNN comments pages ok. edit: If you're not worried about the cookies then can you take the requirement for state mandated popups on any site that uses cookies out of the GDPR, thanks. edit 2: (due to being throttled for wrongthink) According to the GDPR website to comply you must "Receive users’ consent before you use any cookies except stric…

There is no mandate for pop ups on any site. Blame the content providers who are doing it wrong.

Re: Ask HN: Could EU residents comment on how the GDPR has improved their privacy?

#58
A shop belonging to a big electronics chain registered me as a member without my consent.

After I contacted the chain about it, within a few days my information had been erased and they said the clerk did not act appropriately and they'd also contact the shop in question to make sure this is not repeated.

It's a long story, but when purchasing, the payment terminal asks "Member?". If you answer in the affirmative, apparently somehow one becomes a member. In this case, the clerk reached out from behind the counter and pressed the button on my behalf while I was busy putting my card away. The receipt had the text "member" with a membership number and so on.

In retrospect I suspected that the clerk's KPI contains the number of new members. Most people probably won't care enough to raise noise about it.

Before GDPR, and actually before the improved EU privacy laws in general, say, 20 years ago, fixing this would have likely involved navigating some sort of swamp of dark patterns with several phonecalls and tons of queueing, with a long lead time for the removal and so on.

Re: Ask HN: Could EU residents comment on how the GDPR has improved their privacy?

#59

I've used the new laws twice now to close online accounts with companies that were uncooperative or too 'clingy' (looking at you, OVH and Microsoft). Much easier to send a registered letter than waiting on hold or searching for an online option that was deliberately made hard to find, or which may not exist at all. I have also used it to stop unwanted postal ads from local companies. I get to find out how they obtain…

> Much easier to send a registered letter than waiting on hold or searching for an online option that was deliberately made hard to find

This hasn't changed. Every EU country implemented the Data Protection Directive and you could just have sent a letter since the late 90s (the exact date depending on your country).

Re: Ask HN: Could EU residents comment on how the GDPR has improved their privacy?

#60

All marketing email has an unsubscribe link if it didn't before, and you know it actually works now to stop the emails, not just confirm your email address works. You also know you can get all the information a company has on you, and get them to delete it if you need to. I haven't made use of it yet, but I've read of people who have. From inside the business side, I see most companies thinking about GDPR compliance…

> All marketing email has an unsubscribe link if it didn't before

GDPR says nothing about marketing emails. I can only speak for the Netherlands, but our laws about unsolicited commercial communication is what applies there.

What GDPR has to do with it is that they need your contact details to send you anything, so they process personal data. The predecessor to GDPR (called DPD, from the late 90s) also required companies to ask consent if there was no need to process your data for things like fulfilling a contract (same as with GDPR: they only need consent if it's not for a certain set of exceptions).

> You also know you can get all the information a company has on you

This was also the case under the previous law.

Post reply on HN