Ask HN: Could EU residents comment on how the GDPR has improved their privacy?
71–78 of 78 posts
Re: Ask HN: Could EU residents comment on how the GDPR has improved their privacy?
#72Popups everywhere. Insane bureaucracy, even at the doctor. And when it matters, it's just being ignored. Most (medium-sized) companies haven't even realized there is a new law.
I haven't noticed any "insane bureaucracy" at the doctor, but there's a new box to tick in the signup forms > And when it matters, it's just being ignored. Where is that? Though you're welcome to point those out to your country regulator. > Most (medium-sized) companies haven't even realized there is a new law. Actually they have, I was surprised at getting emails from medium sized, non-online business about it
Blanket forced consent in terms "we need to track you because we have a business need, take that or leave", despite being explicitly prohibited in all GDPR-related guidelines is still something you get away with.
Also one word: Facebook.
Re: Ask HN: Could EU residents comment on how the GDPR has improved their privacy?
#73Re: Ask HN: Could EU residents comment on how the GDPR has improved their privacy?
#74My personal stages of gdpr experience: Stage one: these cookie consent popups are empowering. I'm glad the people won. Stage two: I am getting a bit sick of having to understand custom consent forms on every site. Stage three: what have we done, cookie consent has made the internet suck even more! Stage four: I wonder what all this privacy stuff is really about (goes and reads about it). Stage five: The internet is a…
Re: Ask HN: Could EU residents comment on how the GDPR has improved their privacy?
#75Earlier quoted context omitted.
I haven't noticed any "insane bureaucracy" at the doctor, but there's a new box to tick in the signup forms > And when it matters, it's just being ignored. Where is that? Though you're welcome to point those out to your country regulator. > Most (medium-sized) companies haven't even realized there is a new law. Actually they have, I was surprised at getting emails from medium sized, non-online business about it
> > And when it matters, it's just being ignored. > Where is that? Though you're welcome to point those out to your country regulator. Blanket forced consent in terms "we need to track you because we have a business need, take that or leave", despite being explicitly prohibited in all GDPR-related guidelines is still something you get away with. Also one word: Facebook.
But I use ad blocking/cookie blocking so I guess it works the way I want regardless of what they think
Re: Ask HN: Could EU residents comment on how the GDPR has improved their privacy?
#76For many of us software people, it isn't that revolutionary. These are things we should've been doing for a long time, and many of us have been doing.
But many companies are massive and bureaucratic. Everything from random giant companies to schools, hospitals, etc. These people don't really care about 'privacy', and many abused the hell out of people's privacy, many unintentionally (just careless). And since they make up big processors of data it was necessary to have them improve their practices. Now they actually think about how data is being processed rather than just chucking it around.
The GDPR's biggest impact or purpose isn't to reduce online tracking. It's to secure data rights for citizens in general. And the biggest abuses of that didn't happen due to advertising or tracking.
Re: Ask HN: Could EU residents comment on how the GDPR has improved their privacy?
#77Well, the cookie popups have helped me become more selective in my browsing. If they don't make it reasonably easy to opt out, I just don't open the site. But the real benefit is this: Some random online store that i bought something from once decided to send me a spam sms around black friday. One email and 24 hours later, all the data they had about me was deleted. Of course, this only works if you're in europe buyi…
Google do ask for consent where required, but consent isn't required. There's various legal bases for the processing of data according to the GDPR (including for the performance of a contract and for legitimate business interests). Google just invested more in lawyers to use the GDPR strategically so they would have to change as little of their processes as possible.
Companies that don't understand the GDPR or privacy spent a fortune on consultants that milked them for money. Such companies seem to think the GDPR is a doomsday weapon and a revolution. It really isn't.
Re: Ask HN: Could EU residents comment on how the GDPR has improved their privacy?
#78Well, the cookie popups have helped me become more selective in my browsing. If they don't make it reasonably easy to opt out, I just don't open the site. But the real benefit is this: Some random online store that i bought something from once decided to send me a spam sms around black friday. One email and 24 hours later, all the data they had about me was deleted. Of course, this only works if you're in europe buyi…
A few notes: > One email and 24 hours later, all the data they had about me was deleted. You make it sound as if this is new, but this was also possible under the DPD from the late 90s. GDPR didn't improve that. (What helped is that GDPR isn't from the late 90s but was introduced in a year where privacy was already a hot topic, so it was picked up by the media and now companies actually know about it so you don't hav…
GDPR did improve it. Under the implementation by member states of the DPD many required that you can show "duress and/or distress" from continued processing to request erasure. GDPR made it so you don't have to show anything, you can just request it (or, more technically, you can withdraw consent).
And the DPD only said:
> as appropriate the rectification, erasure or blocking of data the processing of which does not comply with the provisions of this Directive, in particular because of the incomplete or inaccurate nature of the data;
Organisations often took a very conservative interpretation of this which wasn't enforced differently by many DPAs in EU states. GDPR Art. 17 is definitely stronger.