Live data from Hacker News

Two years in, GDPR defined by mixed signals, unbalanced enforcement

complianceweek.com

11–20 of 216 posts

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#12

I'm happy to see this as the top post on Hacker News, though would wonder if anyone would be able to provide me with a summary of the article since $399 is a bit steep for me (as in, I can afford it, but it's obviously WAY too much for what's promised by the title). I'd also be interested in case anyone has any thoughts on what the short or long-term outcome of the situation would be. Come to think of it, I'd like it…

You can open it on Incognito mode.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#13

I'm happy to see this as the top post on Hacker News, though would wonder if anyone would be able to provide me with a summary of the article since $399 is a bit steep for me (as in, I can afford it, but it's obviously WAY too much for what's promised by the title). I'd also be interested in case anyone has any thoughts on what the short or long-term outcome of the situation would be. Come to think of it, I'd like it…

At the moment, lawyers and all the scummy industry around the GDPR (whether it's advice/consulting or "consent management") are indeed the only ones making the money.

There is very little enforcement and flawed solutions from the aforementioned industry are allowed to proliferate despite not actually being compliant (the majority of "consent management" solutions are in breach, so they are making money while not even helping their client become compliant).

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#14
This has been a constant headache, not the rules or how to apply it, but our customers still act like there isn't such a thing like GDPR, and actively demand, DEMAND that we put in place functionality that is in clear violation of GDPR, and when you try to inform and explain to them who things work they get mad at me and threaten that they will get a more professional shop to do things for them shrugs

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#15

Has anyone beyond big tech actually figured out what the rules are yet?

The rules are very clear once you look past the fear-mongering. Don't stalk people, and if you want to stalk them you need to ask them nicely and allow them to decline. Don't be careless with user data so you minimize the likelihood of a breach, and if you do get breached then report it to the regulator and cooperate with them.

In fact, "big tech" has figured out how to get around the rules by exploiting the lack of enforcement. The majority of big tech is knowingly not GDPR-compliant.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#16
post #11
post #2

We care about your privacy notices have become the bane of my life.

Disrespectful web developers have become the bane of my life. Be thankful that GDPR exposes them, and look for alternatives.

Setting aside GDPR for a moment, the cookie thing just means that if I want to use these websites, I have to enable cookies so that I can dismiss the cookie dialog.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#17
post #11

Earlier quoted context omitted.

Disrespectful web developers have become the bane of my life. Be thankful that GDPR exposes them, and look for alternatives.

Setting aside GDPR for a moment, the cookie thing just means that if I want to use these websites, I have to enable cookies so that I can dismiss the cookie dialog.

Again, only because of incompetent and/or immoral developers.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#18

We value your privacy. Like, it's valuable. We sell it for money. We're going to nag you until you click this button so we can't get in trouble for profiting off the data you give us. Good legislation is important to let us penalize bad actors—does any one know of any accounts of some bad actors getting stopped by the GDPR? What do you guys think: are there laws that should be in place to incentivize privacy-preservi…

> We're going to nag you until you click this button so we can't get in trouble for profiting off the data you give us.

That is explicitly against the regulation. Consent should be freely given otherwise it's invalid.

The problem is that there is no enforcement around this (despite it being very easy to detect this behavior at scale by running a web scraper) so they keep doing it and profiting off it.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#19
It is worth pointing out GDPR is really two sets of laws - one around data security and breaches, and another set of laws around privacy. It's the second set of laws that get the most criticism for their opaqueness, but I don't know if they are better or worse than the first.

They probably should have held off completely on the second set - the upcoming ePrivacy regulations are promised to actually do something, rather than just provide a really frustrating and opaque set of consent guidelines.

As it is now, the law doesn't require anyone to actually stop what they are doing. The only difference now is you have to retain a lawyer to do it.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#20
I think GDPR has its heart in the right place.

I don't think it really helps and I suspect that is because users themselves really don't know what is actually happening behind the scenes and no amount of banners or otter things changes their level of knowledge.

And I fear even if they know, users don't care and are happy to click past a banner / trade their privacy for free things.

GDPR seems to play out as a strangely legally mechanical beast that people are largely disconnected from.

Post reply on HN