Live data from Hacker News

UK to depart from GDPR

lawgazette.co.uk

541–550 of 659 posts

Re: UK to depart from GDPR

#541
post #115

‘too many businesses and organisations are reluctant to use data – either because they don’t understand the rules or are afraid of inadvertently breaking them’ TBH I'm glad companies stay away from my data if they don't know how to get consent, store data securely, or even what those things mean.

Most of these companies wouldn't know how to make much use of the data anyway. My experience working with companies and analytics (even did an analytics startup some years back) is that they haven't a clue about how to actually use it and just heard that more data is somehow better. That to me sounds like they're most likely to sell the data, since they don't know how to use it themselves. Better these companies have…

Companies still need some basic data for whatever problem they're solving, right?

As an example, let's say I want to launch a blogging platform. You need some basic tables (data) like User, Posts, Tags, etc. I'd consider this data the business needs for core business. Does there need to be some GDPR compliance thing?

Anecdotally a dumb app I built I was worried about EU visitors and just wanted to block them instead of figure it out (yea yea maybe that's not the right approach but I'm sure the sentiment is common).

Re: UK to depart from GDPR

#543

Earlier quoted context omitted.

The EU as a political union exists a little over a decade, if anything the UK never adapted to it.

Mistaking the EU, the political union as an evolved form of the Rome treaty, with Euro, the coin. All that with the tone of absolute certainty and authority. Hacker News has reached new lows :(

HN has always been bottom of the barrel. Bunch of people repeating memes to each other.

Re: UK to depart from GDPR

#544
post #539

Earlier quoted context omitted.

Apparently those supporting GDPR would rather have the EU fine Google than to ensure small businesses can survive and be productive with technology, even when the fine to Google is a small amount compared to how much Google makes in the EU. Makes perfect sense, no?

Is that a sarcastic comment? Because GDPR allows for liquidating fines, even for Google. I believe it has a cap of 2% annual global turnover, per infraction, or something similar. Problem is, GDPR is not enforced. I haven't heard of small companies being investigated, let alone having any fines imposed, even when blatantly violating GDPR.

It’s the law, and it places undue burden on small companies that may not have the technical resources to modify their site/apps/data as expected, as many of them contracted out the work initially at great expense.

An email address is considered PII, so if users request their data be deleted, the small business is honest and says they can’t, and the user and others raise this to the government, you think that small company won’t be fined? That company, worried about doing things illegally, may end up giving a bunch of money to a contractor to fix their application- and for what? To allow users to request that their email address be anonymized or removed? That’s stupid.

Re: UK to depart from GDPR

#545
post #39

Well say goodbye to EU data adequacy. Although to be honest it probably wouldn’t have survived the first court case given the UK state’s addiction to snooping.

> UK state’s addiction to snooping

GDPR has nothing to say on state snooping and if you think Germany or plenty other members aren’t.... I’ve got some bad news for you

Re: UK to depart from GDPR

#546
post #389

Earlier quoted context omitted.

I'm totally good with there being laws about this as I too want to see less tracking and data sharing. But the implementation is terrible and anybody who thinks that it's fixed anything at all is just kidding themselves. I would rather bad actors were punished and enforced cookie banners were eliminated.

Well, that's why the GDPR tried to get rid of them. Of course people now put up GDPR barriers ;-) It's really hard to legislate against something that some people really want to do :-/

I think we can both agree on that. People have reacted somewhat negatively to my original comment, but I suspect cookie banners have done more harm than good on balance. It’s one of those things where the spirit of the movement got lost.

We were discussing something in a similar vein the other day regarding a security form for an enterprise contract and my reoccurring response was “officially or actually?” There tends to be a big gap between official compliance and what was originally desired.

Many years ago I worked with a mega mega corp that required a complex form with every change request, but they still ran my script that escalated my database permissions because they ran it as root.

Re: UK to depart from GDPR

#547

Earlier quoted context omitted.

Consider lawful basis. Does your processing fall under the lawful basis you think it does? Who the hell knows. Making an educated guess as to what the regulators and courts will think is legal scholarship, one of the most expensive professional services money can buy. And even if you get billed for hundreds of hours of the most premium legal minds thinking about it they can still be wrong. Words like “reasonable” and…

Apparently those supporting GDPR would rather have the EU fine Google than to ensure small businesses can survive and be productive with technology, even when the fine to Google is a small amount compared to how much Google makes in the EU. Makes perfect sense, no?

There’s nothing written in GDPR that would prevent a small business from surviving and being productive. It’s also important to understand that the law enforcement is business friendly in general: if you don’t do stupid thing intentionally, but occasionally make a mistake, no one will punish you.

Re: UK to depart from GDPR

#548

Earlier quoted context omitted.

> If anything I think it is rather unfair to hear people from other EU countries treating this process as something along the lines of 'suits them' and 'they've made their bed'. From my perspective, it's more like "it was inevitable". The people pushing for Brexit would never give up. So the choice was either leave now, or keep talking for the following years/decades/centuries about how the evil EU oppresses the UK,…

"everything would be perfect if only EU stopped interfering with our perfect country" will disappear from political speech. That doesn't seem to be disappearing. My guess is we will be hearing a lot more about the EU for the foreseeable future.

One or two election cycles, but afterwards it will be too boring to hear the same excuses.

Soon after dissolution of Czechoslovakia, people in Slovakia blamed Czechs for all kinds of things. (We had an agreement that neither side will use the old federal flag; they kept it. We had an agreement that the national treasure will be split proportionally; they decided to keep it all. Plus a few more things. I am sure the other side also had their complaints.) A decade later, after most politicians from that era retired, no one mentioned this anymore. People who were not yet adult during the federation simply don't care; it's ancient history for them, like complaining that your garden does not have nice flowers because dinosaurs once stomped on it. Yeah, but what did you do about it since then; you had enough time to do something, right?

I feel like an old person just for mentioning the old issues. Similarly, ten or twenty years later, Farage will be just some uncool old grandpa no one cares about. It may be hard to imagine, but it will happen.

Re: UK to depart from GDPR

#549
post #539

Earlier quoted context omitted.

Apparently those supporting GDPR would rather have the EU fine Google than to ensure small businesses can survive and be productive with technology, even when the fine to Google is a small amount compared to how much Google makes in the EU. Makes perfect sense, no?

Is that a sarcastic comment? Because GDPR allows for liquidating fines, even for Google. I believe it has a cap of 2% annual global turnover, per infraction, or something similar. Problem is, GDPR is not enforced. I haven't heard of small companies being investigated, let alone having any fines imposed, even when blatantly violating GDPR.

Just because you haven't heard of it doesn't mean it doesn't happen..

https://gdpr-fines.inplp.com/list/

https://www.enforcementtracker.com/

Re: UK to depart from GDPR

#550
post #500

Earlier quoted context omitted.

> Developers have to have mechanisms in place to delete gdpr data when required and not store data that's not required for you goals Purely anecdote, but zero companies I know in Germany, Italy or France are doing this. (The ones in Switzerland are.) There is a cosmetic fix that produces an email so there is something to show a regulator if they come knocking. The logic being investing anything more than that is a cr…

You must work with some pretty poorly organised companies. I work with a lot of French, Belgian and German companies and they pretty much all have proper procedures and tools for this. In France in particular the right to access/change/delete any and all data a company has on you was there long before GDPR (by decades) so most serious company are well used and prepped for it.

> pretty poorly organised companies

They range from start-ups to national champions, but I won't disagree with you on the poor organization of most European companies point. Everyone one re-papered existing systems to some degree of compliance. Given nobody agrees on what full compliance is, they're all right in their own ways.

Post reply on HN