Live data from Hacker News

UK to depart from GDPR

lawgazette.co.uk

511–520 of 659 posts

Re: UK to depart from GDPR

#511
post #459

Earlier quoted context omitted.

In practice though with the GDPR, sites either just 403 everyone in the EU to avoid complying, or just shower you in javascript cookie notifications, making your browsing experience more bloated, slow and insecure.

The GDPR is not a law that only regulates the internet. The GDPR applies to all processing of all personal data regardless of whether that's pieces of paper in a filing cabinet or an entirely online social network.

That's not true unfortunately. It has a blanket exception for anything remotely government related (meaning government itself and anyone the government authorizes), and in fact guarantees far more and wider access to your most sensitive data, not less. And it allows the government to authorize whoever they please to not just keep more data about you, tighter and more closely linked together, but to keep this from you, and to prevent you from doing anything about it. Which, since the process now exists, they have prodigiously used.

Insurance? Private doctor? Youth services? Family (or any other) court? Pharmacy (in most of Europe)? Police (even in the most trivial of cases, and without judicial approval, and of course without verification or recourse)

Worse than that: the exception goes further than merely keeping data as well. Insurance company wants to change/add to your medical record? Immediately? Doctor? Court? Police? All can change your medical file, both adding and deleting (sometimes limited to what they added themselves). YOU want to change it? Not possible!

Weird since insurance company access to your data, and "the right to be forgotten" was one of the main selling points of this legislation, but since insurance companies are semi-government in almost all of Europe these days, a lot of them fall into the blanket exception.

And of course, you yourself ... cannot access this data. You cannot see it (sorry "you can, unless there's a reason not to let you see it", wanna bet there's always a reason?). For particular parts (espectially names, for example which doctor put something there about you are kept secret from you). Thankfully these institutions hate eachother, so there is some protection left because if anyone wants this data, they have to file requests in 5 different places. But there is no more legal protection against this happening.

It is now far easier, in the Netherlands, to get a serious crime stricken off your judicial record than, say, getting a doctor or pharmacist's claim that you falsely came in for a heart problem out of your medical file, say to threaten or attack them for painkillers, or even just getting the name of which doctor put that there (and of course such misleading information can kill you if you ever really do have a heart problem, and god help you if you need pain killers or ...)

GPDR protects you from Amazon offering you gift ideas for your kids' birthday if you object to that. You want a mental health stay 40 years ago to not be used in a family court case against you? THAT it makes MUCH easier. Faking such a thing and using it in a court case against you, that, too, it makes a lot easier.

Re: UK to depart from GDPR

#512

Earlier quoted context omitted.

> The privatisation of British rail has been a disaster Train company profits count for about 2% of the total cost of the ticket, and (pre covid) the network carried more than twice as many passengers as it was under BR - nearly 2 billion journeys a year vs a steady 800m in the 70s through 90s. in terms of distance, pax-km 1970 36b 1980 35b 1990 40b 1997 42b (end of BR) 2010 64b 2018 81b Since 1997 that's a 90% incre…

I'm not sure where you're getting your figures from. Here's a more representative view: https://fullfact.org/economy/how-much-does-government-subsid... Government subsidies have tripled since privatisation and fares have risen by 20% after inflation. That doesn't seem like a win for efficiency. And of course it's the customer who bears the cost - which aren't just economic, but also social, because good public infras…

Those specific figures come from the sheet "Rail subsidy per passenger mile by Train Operating Company (TOC): DfT franchised train operators: 2015/16"

Note this importantly doesn't include Scotland, Wales, Merseyrail (public) or TFL (public)

Rail subsidy jumped after railtrack was replaced with nationalrail, and the legacy of decades of underfunding in rail under BR was apparent. That underfunding is obviously going to happen under a tory government interested in cutting short term costs. You can see that as of 2015 subsidy per passenger mile was about the same as it was in the 80s and 90s[0]

Rail subsidy is split into two parts

1) Track costs 2) Service costs

Your figures are including major capital expenditure - specifically HS2 and Crossrail, so not really comparable with subsidies in the 70s and 80s when there weren't massive capital programmes and expansion.

I'm less concerned about track maintenence costs or track capital costs -- that's like the government paying for road maintenance or new motorways - it's good. It's the service subsidies that interest me. Basicalyl how much is the taxpayer using to subsidise rail travellers (who tend to have higher income and higher wealth than average), and during the 6 years I have data on, those dropped by £1.4 billion.

Remember that under BR there were competing sectors - intercity, regional railways, network southeast, all of which were shit. Now there are competing franchisees, some of which are shit, but we often get a choice (Virgin vs Chiltern vs London Midland for London-Birmingham, XC vs TFW for Crewe-Bristol, etc. This means more choice and cheaper fares for me, the passenger).

In 2015/16 the franchise "GTR (Thameslink etc)" pays £278m for the privilige of running trains through central London. Meanwhile Northern, which have very few routes that pay their way, get paid £122m from central government. You could argue that Grant Shapps would be better running these services, I'm not convinced.

Effectively Brighton->London commuters are subsidising rural travellers in Yorkshire. You could argue this shouldn't happen, and those commuting into London for high paying jobs should have cheaper fares, at the expense of fewer services in the North. That's a very Thatcherite view, but that's ok, everyone's entitled to a view.

APT predated privitisation by 2 decades so I'm not sure what that has to do with anything. Virgin ordered the class 390s.

It sounds like you don't like the state of the rail industry in Britain in the 80s and 90s, which is reasonable. It's hardly the fault of privitisation didn't start until 1993 and didn't begin operation until about 1997

[0] https://en.wikipedia.org/wiki/Impact_of_the_privatisation_of...

Re: UK to depart from GDPR

#514
post #95
post #28

For me the biggest flaw of GDPR that it does not distinguish between something done as a business to make money and something done non-profit, as a hobby project, etc. GDPR killed forums, etc. everything moved to Facebook groups, where people agree to whatever Facebook wants. Who will create forum for a community if one has to deal with all the bureaucracy, "right to be forgotten", data accuracy checks, data export r…

What kind of personal data do you need to store for a forum ? For what purpose ? > Who will create forum for a community if one has to deal with all the bureaucracy, "right to be forgotten" Most forums are created with softwares handling everything, virtually nobody creates a forum from scratch with his own tech stack. > If kids leave they clothes in kindergarten or school, can clothes be signed with kid first and la…

> Most forums are created with softwares handling everything, virtually nobody creates a forum from scratch with his own tech stack.

If you don't host the forum yourself you need a data processing agreement with the hoster to be GDPR compliant. If you want to load the user image from Gravatar, you need a DPA with Tumblr. Good luck with that.

Reading contracts and laws in good faith is a pretty bad idea if you don't like being sued and loosing. Always read laws in a way as if someone was going to use it just to ruin your day.

Re: UK to depart from GDPR

#516
post #386
post #377

Earlier quoted context omitted.

The shock of being well ahead of the EU on vaccinations?

Broken clocks are right twice a day. Though I agree that involving both the military and the NHS has resulted in being enormously successful at rolling out the vaccine. Let’s hope that the NHS gets properly funded and doesn’t get privatised. Because the US vaccination rollout is a shambles.

Is it? They’re about 4th globally, and way ahead of the EU.

Re: UK to depart from GDPR

#517
post #115

‘too many businesses and organisations are reluctant to use data – either because they don’t understand the rules or are afraid of inadvertently breaking them’ TBH I'm glad companies stay away from my data if they don't know how to get consent, store data securely, or even what those things mean.

Consider lawful basis. Does your processing fall under the lawful basis you think it does? Who the hell knows. Making an educated guess as to what the regulators and courts will think is legal scholarship, one of the most expensive professional services money can buy. And even if you get billed for hundreds of hours of the most premium legal minds thinking about it they can still be wrong.

Words like “reasonable” and “legitimate” in the law are not something it is safe for a layperson to reason about. They have specific meanings depending on the nuances of case law, judicial understanding of legislative intent, ideological leanings of the judge you happen to draw, etc.

No company is competent at this, some just have enough money at stake and enough to spend on lawyers that they’re willing to risk it.

Re: UK to depart from GDPR

#518
post #386
post #377

Earlier quoted context omitted.

The shock of being well ahead of the EU on vaccinations?

Broken clocks are right twice a day. Though I agree that involving both the military and the NHS has resulted in being enormously successful at rolling out the vaccine. Let’s hope that the NHS gets properly funded and doesn’t get privatised. Because the US vaccination rollout is a shambles.

>the US vaccination rollout is a shambles

Japan: You guys have vaccines?

In all honesty, this statement is fairly close to being hilariously wrong. The US vaccinates more people per day than any other country in the world. The reason why the UK has a higher per-capita vaccination rate is A) there's less of you to vaccinate, and B) the UK isn't doing two doses. The former makes the rollout easier - there are countries like Israel where they're close to vaccine herd immunity as they simply needed fewer doses. The latter is a calculated risk only somewhat supported by the available medical data. I don't expect every country to adopt First Dose First, especially if they've already given two doses to high-risk populations that would benefit from getting half their protection sooner.

Trust me, there's plenty of other things you can harangue the US about all day - vaccines aren't one of them.

Re: UK to depart from GDPR

#519
I'm broadly in favour of any consumer protective legislation like the GDPR, but I feel that the GDPR has been misinterpreted by many, in both directions.

Those who ultimately respect user privacy and want to do the right thing are often paralysed by process and making sure that they absolutely can't be sued, rather than being able to show respect for data and best practices but still getting things done.

Those who ultimately don't respect user privacy use it as an excuse. They plaster their services with GDPR notices, and then ignore the spirit of the law and sweep up all the data they want, regardless of whether they need it or should have it, but of course this is invisible to users so nothing happens about it.

I wonder if this disconnect comes from the enforcement? I'd like to see a few high-profile cases that set out some precedents for what is and what isn't a breach of GDPR.

Re: UK to depart from GDPR

#520

I'm broadly in favour of any consumer protective legislation like the GDPR, but I feel that the GDPR has been misinterpreted by many, in both directions. Those who ultimately respect user privacy and want to do the right thing are often paralysed by process and making sure that they absolutely can't be sued, rather than being able to show respect for data and best practices but still getting things done. Those who ul…

Don't forget the people that use it as an excuse to not do what they simply don't want to do. "Sorry, we cannot contact you via email, GDPR, you understand? You have to come to us and have an awkward sales talk in order to get your trivial information."
Post reply on HN