Live data from Hacker News

Two years in, GDPR defined by mixed signals, unbalanced enforcement

complianceweek.com

121–130 of 216 posts

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#121

Personally I am just annoyed by the cookie warning on every site. Gdpr does not apply to vast portions of the internet.

>Gdpr does not apply to vast portions of the internet

Europe wants it to apply to anything a European might touch.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#122

Earlier quoted context omitted.

> The majority of these aren't actually compliant There is insufficient evidence attempting to comply with GDPR is worth the cost.

Absolutely, given the current lack of enforcement. However, if you're going to be in breach, you might as well improve UX and not bother with the whole "consent management" thing, not to mention that the TrustArc garbage solution doesn't seem cheap.

But then it's much more apparent that you are in breach. If you pretend to care then the chance of being caught is much lower.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#123

Earlier quoted context omitted.

Not for this regulation. Business considerations do not matter, only technical ones.

The true hallmark of an ill-conceived law.

Letting companies opt-out of a regulation purely because it hurts their business model sounds much more ill-conceived to me.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#124

Earlier quoted context omitted.

Stalking is collecting any information, that either by itself or combined with other information can be used to identify someone with reasonable probability. IP addresses, browser/device details (fingerprinting, etc), usage patterns can fall into this category.

By that definition, literally everybody in real life is stalking me just by seeing what I look like. That's not a terribly useful or reasonable distinction.

Human memory does not constitute a storage device for the purposes of GDPR.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#125

Earlier quoted context omitted.

Not for this regulation. Business considerations do not matter, only technical ones.

The true hallmark of an ill-conceived law.

In this case you could say anti-drug-trafficking laws are ill-conceived because they go against the cartels' business models.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#126
post #20

I think GDPR has its heart in the right place. I don't think it really helps and I suspect that is because users themselves really don't know what is actually happening behind the scenes and no amount of banners or otter things changes their level of knowledge. And I fear even if they know, users don't care and are happy to click past a banner / trade their privacy for free things. GDPR seems to play out as a strange…

> users don't care and are happy to click past a banner / trade their privacy for free things. Are we discounting the possibility that users make a rational choice that we happen not to like?

Tough question. For some things, I'd say that informed consent is hard to give - if you consent, you're not informed.

I don't believe that the average user is making informed choices. The choices may be rational as long as the users don't understand the consequences. It's perfectly rational to trade in your life savings for a fancy meal if you don't understand what "life savings" means.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#127
post #120

Earlier quoted context omitted.

Then maybe we shouldn't be making laws to force things "we happen to like" to everyone

I don't think GDPR forces you to choose not to share information. You simply get a a mechanism to make that choice. IMO it is a flawed and wonky mechanism. Still I'd prefer a the option, later if nobody cares then maybe remove the choice.

It forbids the exchange of information for providing service. There is no choice

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#128
post #22

Earlier quoted context omitted.

The rules are very clear once you look past the fear-mongering. Don't stalk people, and if you want to stalk them you need to ask them nicely and allow them to decline. Don't be careless with user data so you minimize the likelihood of a breach, and if you do get breached then report it to the regulator and cooperate with them. In fact, "big tech" has figured out how to get around the rules by exploiting the lack of…

> Don't stalk people, and if you want to stalk them you need to ask them nicely and allow them to decline Ok, that's nice in a fantasy world, but in the real world a lot of people/sites rely on ad revenue, and ad revenue for the most part, requires tracking built in. So now if you legally force me to allow users to decline "stalking" you are basically allowing users to decline my monetization model and use my website…

DuckDuckGo does ads without tracking

In fact, every advertisement outside of the web works without tracking/stalking the consumer. At most, you get a discount code for "seeing this ad on X place"

> Why can't I say: "accept that my site is ad-supported or don't use my site?"

Because that's the equivalent of me giving you my address, dob, SSN, etc just for entering your store

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#129

Earlier quoted context omitted.

The business model of Google isn't a failed business model. What the GDPR does do, quite successfully, is build a moat around Google so wide and deep as to minimize competition with them, because they're one of the few firms that can both (a) afford the engineers with the technical expertise to comply with the law while accomplishing their goals and (b) afford the lawyers to address the issue when they fail at the fo…

> afford the engineers with the technical expertise to comply with the law while accomplishing their goals Google is in breach of the GDPR as it stands, so no. > afford the lawyers to address the issue when they fail at the former Potentially, though again a clear-cut breach like theirs should result in a fine regardless of how much money they throw at the problem. As far as building a moat, I'm not sure. Whether it'…

> Google is in breach of the GDPR as it stands, so no.

I don't believe that is true. What is your source?

They were fined in Jan 2019, but are they still out of compliance? If yes, why are they not being continuously fined?

> you either break the law or you don't.

That's the result on the other side of a trial, sure.

Which is why good lawyers are so important.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#130

GDPR was known to be, is known to be, and will known to be a shit law that's not tied to reality. It did have some good (allowing you to know what they have on you in general, and asking them to delete some of that), but the rest is just bad, bad, bad. I wish people would be rational when supporting privacy increasing things. GDPR could have been much better and it saddens me that it was ruined, and defended by, zeal…

In a way, I'm glad this law exists. My competitors spend so much time to be compliant. I just ignore the law and spend my time on improving my SAAS instead. They all will go bankrupt and my startup gets more and more users every day.
Post reply on HN