Live data from Hacker News

Two years in, GDPR defined by mixed signals, unbalanced enforcement

complianceweek.com

171–180 of 216 posts

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#171

Earlier quoted context omitted.

I thought that’s what everyone thought back then. At least all my friends were like, the lawyers will have a good time and be the only ones benefiting from this

HN was (is) super into GDPR and any dissonance was (is, but fortunately less nowadays) quickly downvoted.

A person commented and asked me about suggestions, but deleted his comment before I could answer so here it is anyways:

Super quickly (I'm sure you have heard of, or can quickly use a search engine to find the commonly listed issues):

Damages: damages need to be scaled according to the company size, severity and amount. GDPR was created to punish Big Players, but the wording that would have fit them is equally (and should be, laws should be equal) applied to small companies resulting in an impedance mismatch. Frankly, the damages are too small for the Big Players, but insane to the small ones. GDPR also does not apply to the state, but holy shit it fucking should!

Enforcement: it needs to be equally enforced and you need to be able to sue by yourself over it instead of just limiting it to a state organisation.

Data: it should be data that is directly tied to you, ie leave the normal web logs etc out of it. PII is just a sham as it's defined today. A factor of usage also needs to play into it, ie normal web server ip logs that are separate and don't feed into a user specific connection into a database should not be a consideration.

Access: access _needs_ to be able to be done online if the data is collected or transferred online. Ie no this "you need to physically mail us a certified mail with your id" shit. GPDR is a fucking failure in this aspect. Also no required strong authentication: access should be just directly through your account you can access normally without strong authentication.

Usage: GDPR does not allow you to trade tracking for access (ie monetisation of content is almost impossible if you care about user privacy): this is insane. GDPR also supposedly does not allow for those complicated "accept all or modify your preferences" windows, but it should have no saying in that: if a site wants to make the experience painful, that's up to them. It is up to the user to select if they want to use that site or not.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#173

GDPR was known to be, is known to be, and will known to be a shit law that's not tied to reality. It did have some good (allowing you to know what they have on you in general, and asking them to delete some of that), but the rest is just bad, bad, bad. I wish people would be rational when supporting privacy increasing things. GDPR could have been much better and it saddens me that it was ruined, and defended by, zeal…

A person commented and asked me about suggestions, but deleted his comment before I could answer so here it is anyways:

Super quickly (I'm sure you have heard of, or can quickly use a search engine to find the commonly listed issues):

Damages: damages need to be scaled according to the company size, severity and amount. GDPR was created to punish Big Players, but the wording that would have fit them is equally (and should be, laws should be equal) applied to small companies resulting in an impedance mismatch. Frankly, the damages are too small for the Big Players, but insane to the small ones. GDPR also does not apply to the state, but holy shit it fucking should!

Enforcement: it needs to be equally enforced and you need to be able to sue by yourself over it instead of just limiting it to a state organisation.

Data: it should be data that is directly tied to you, ie leave the normal web logs etc out of it. PII is just a sham as it's defined today. A factor of usage also needs to play into it, ie normal web server ip logs that are separate and don't feed into a user specific connection into a database should not be a consideration.

Access: access _needs_ to be able to be done online if the data is collected or transferred online. Ie no this "you need to physically mail us a certified mail with your id" shit. GPDR is a fucking failure in this aspect. Also no required strong authentication: access should be just directly through your account you can access normally without strong authentication.

Usage: GDPR does not allow you to trade tracking for access (ie monetisation of content is almost impossible if you care about user privacy): this is insane. GDPR also supposedly does not allow for those complicated "accept all or modify your preferences" windows, but it should have no saying in that: if a site wants to make the experience painful, that's up to them. It is up to the user to select if they want to use that site or not.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#175

Has anyone beyond big tech actually figured out what the rules are yet?

What makes you think big tech follows the rules?

They continue to operate and are not bogged down in regulation. Even if there are unofficial rules of what matters and what doesn't, they have figured out those rules.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#176
post #17

Earlier quoted context omitted.

Again, only because of incompetent and/or immoral developers.

How, exactly, is a developer supposed to change state in a stateless protocol to denote that you've dismissed the cookie dialog if the user has disabled the feature that allows the developer to add state to the stateless protocol?

I never dismiss those dialogs anyway. Just make sure your site works with the browsers reader mode and I’m fine.

But on the top of my head only display the dialog if the browser cache is cold. Could embed a timestamp in some cachable resource. (Edit: Perhaps this counts as a “cookie“ in the legal sense)

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#177
post #98
post #49

Earlier quoted context omitted.

There is a privacy benefit to adding friction to spreading personal data around everywhere. At the margin, some services will decide not to bother processing non-essential personal data just to avoid the paperwork. And really, that's one of the excesses that GDPR was a reaction to: that the "default" was "track everything in case the data magically becomes valuable," and now the it's become "perhaps not."

A lot of GDPR can be summarized as "GDPR makes PII into high-grade radioactive waste. You want the least of it, and take care of the remaining bits you end up with"

Relevant: https://idlewords.com/talks/haunted_by_data.htm

(Maybe you were familiar). The closing is particularly worth taking in:

> Finally, don't be surprised. The current model of total surveillance and permanent storage is not tenable.

> If we keep it up, we'll have our own version of Three Mile Island, some widely-publicized failure that galvanizes popular opinion against the technology.

> At that point people who are angry, mistrustful, and may not understand a thing about computers will regulate your industry into the ground. You'll be left like those poor saps who work in the nuclear plants, who have to fill out a form in triplicate anytime they want to sharpen a pencil.

> You don't want that. Even I don't want that.

> We can have that radiant future but it will require self-control, circumspection, and much more concern for safety that we've been willing to show.

> It's time for us all to take a deep breath and pull off those radium underpants.

I'm not sure it came in the form of a single event (though I can think of some candidates -- the cambridge analytica scandal made a big impression for one), but it's clear to me at this point that the warning was ignored, and our industry has missed the window for self-regulation.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#178
post #24

I would pay a subscription to a news site if they spent all their time evaluating 2-5 year old events and determining which side was right. 2 years ago comments of "this will only benefit the lawyers" would be -50 points. Turns out... actually yeah.

Reminds me when the EU "Fixed" Cookies and now we have these stupid click-through warnings everywhere that have pretty much ruined the user experience. Root cause: people passing laws they have idea what about.

Nothing about the EU law requires sites to put up cookie warnings and degrade the ux. They choose to do that.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#179
post #136

Earlier quoted context omitted.

Tough question. For some things, I'd say that informed consent is hard to give - if you consent, you're not informed. I don't believe that the average user is making informed choices. The choices may be rational as long as the users don't understand the consequences. It's perfectly rational to trade in your life savings for a fancy meal if you don't understand what "life savings" means.

I wonder how much information can be provided, much of the "giving your data" is really about the side effects and possible consequences.... But you can only tell people so much. Just saying "hey you're giving google your location" (just a generic example here) ... honestly if that's all I know ... so what? But really the larger issues are other implications. That's a hard thing to explain.

Exactly, and I think we're usually way off intuitively.

For example when considering how many facts of what nature I'd need to individually identify you. SSN? Ok, done, everybody knows that. But how far do I get with birth date, height and city? What if I add one chronic health issue, no matter how small? Chronic sinusitis, born on August 8th, lives in $city and is 186cm? In most cases, I probably don't even need all four.

But most people intuitively don't think about it in combination, they figure "oh so you know I live in $city, big deal, so do a million other people", "oh so you know my birthday, well a million other people in the country have that birthday".

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#180
post #79

Earlier quoted context omitted.

No, there's no protection for failed business models, as there should not be.

A business model that fails because you explicitly make them illegal isn't exactly a failed business model. The lawmakers made them fail and they either knew it was going to happen or were incompetent.

> A business model that fails because you explicitly make them illegal isn't exactly a failed business model.

It literally is, by definition. Any business success has to happen within the legal context it exists in.

> The lawmakers made them fail and they either knew it was going to happen or were incompetent.

I could reword this as "the elected representatives of the people decided that certain business models were undesirable and anti-consumer, so legislated against them".

Post reply on HN