Live data from Hacker News

UK to depart from GDPR

lawgazette.co.uk

551–560 of 659 posts

Re: UK to depart from GDPR

#551
post #459

Earlier quoted context omitted.

The GDPR is not a law that only regulates the internet. The GDPR applies to all processing of all personal data regardless of whether that's pieces of paper in a filing cabinet or an entirely online social network.

That's not true unfortunately. It has a blanket exception for anything remotely government related (meaning government itself and anyone the government authorizes), and in fact guarantees far more and wider access to your most sensitive data, not less. And it allows the government to authorize whoever they please to not just keep more data about you, tighter and more closely linked together, but to keep this from you…

I've never heard this criticism of GDPR before, and a couple of cursory Google searches didn't yield anything supporting what you're claiming. Do you have a source for that?

Re: UK to depart from GDPR

#552
post #464

Earlier quoted context omitted.

Do you really think those websites actually check if you "gave consent" before tracking you?

It feels good to not agree successfully in the lack of a "I don't agree" button. I block their cookies anyway. :) I need to find better ways to mess with their fingerprinting though, or maybe throw back some bogus cookies at them with badly-formatted data instead of blocking them.

Is this something people do? Is it possible for a user to edit a cookie in a malicious way? Do servers typically trust cookies they have placed on a user's machine?

Re: UK to depart from GDPR

#553
post #539

Earlier quoted context omitted.

Is that a sarcastic comment? Because GDPR allows for liquidating fines, even for Google. I believe it has a cap of 2% annual global turnover, per infraction, or something similar. Problem is, GDPR is not enforced. I haven't heard of small companies being investigated, let alone having any fines imposed, even when blatantly violating GDPR.

It’s the law, and it places undue burden on small companies that may not have the technical resources to modify their site/apps/data as expected, as many of them contracted out the work initially at great expense. An email address is considered PII, so if users request their data be deleted, the small business is honest and says they can’t, and the user and others raise this to the government, you think that small co…

I think you are describing very hypothetical situations.

If you know how to get a company fined, could you please share, so I can report and have action taken against companies that violate and misuse personal data?

Re: UK to depart from GDPR

#554

Earlier quoted context omitted.

Most of these companies wouldn't know how to make much use of the data anyway. My experience working with companies and analytics (even did an analytics startup some years back) is that they haven't a clue about how to actually use it and just heard that more data is somehow better. That to me sounds like they're most likely to sell the data, since they don't know how to use it themselves. Better these companies have…

Companies still need some basic data for whatever problem they're solving, right? As an example, let's say I want to launch a blogging platform. You need some basic tables (data) like User, Posts, Tags, etc. I'd consider this data the business needs for core business. Does there need to be some GDPR compliance thing? Anecdotally a dumb app I built I was worried about EU visitors and just wanted to block them instead…

"Does there need to be some GDPR compliance thing?"

Sounds like you have to learn something before starting a business.

Re: UK to depart from GDPR

#555

Earlier quoted context omitted.

It's not inevitable, but the current government appears to move in that direction intentionally. - The EU exit was, among other things, accused of being a way to relax regulation and legislation to degrade product standards to a US-like level. Chlorinated chicken was a big item on everyone's discussion agenda a while back. This is now evidently happening. - The government is severely underfunding the NHS, despite pay…

The US is hardly some low regulation capitalist utopia. The US regulatory code is enormous. Plenty of self-proclaimed "Europeans" think it is, but in my experience they often know relatively little about the issues in question and are just parroting cultural talking points they picked up elsewhere. Indeed, you seem to admit that here, when you state that you got your views of what British people believe from your "ne…

1) I think the NHS is a red line for many people in the UK, whereas criticising the EU has been a national sport since before there was an EU. I think you are misinformed

2) left wing journalists? For what newspaper? The UK newspaper industry is dominated by right wing papers. I think international readers may get there wrong idea about it because they see the guardian online... because the guardian is free it gets shared a lot. If you want to see a typical British newspaper try the Daily Mail (Don't take this as a recommendation!)

3) The idea that the Corbyn election defeat was mostly about rail nationalisation is one of the most absurd things I have ever read.

4) The businesses I work with spent trivial sums on GDPR.

Re: UK to depart from GDPR

#556
post #553

Earlier quoted context omitted.

It’s the law, and it places undue burden on small companies that may not have the technical resources to modify their site/apps/data as expected, as many of them contracted out the work initially at great expense. An email address is considered PII, so if users request their data be deleted, the small business is honest and says they can’t, and the user and others raise this to the government, you think that small co…

I think you are describing very hypothetical situations. If you know how to get a company fined, could you please share, so I can report and have action taken against companies that violate and misuse personal data?

Since you want everyone to be fined, why not start with YCombinator? You can ask them for a list of all of their PII removal requests and to see proof that it was all removed.

I’m sure that’ll go over well.

Then maybe you can submit an Ask HN to see how many startups will self-report to you.

There are over 26M small businesses in the EU. You’d better get started...

By the way, GDPR isn’t just about misuse of PII, it’s about use of PII after it’s been asked to have been removed; and most sites use email addresses as usernames which are PII, so that’s all over the application logs, comments, etc. and when people submit a PII removal request, you can’t share or store the PII in the request itself, so better not use Slack, email, etc. and accidentally refer to the PII to be removed. If you do and need to follow-up again with clean-up, don’t refer to it then either, or you could get stuck in a endless loop of PII removal. Also, how do you know you removed the PII of the user who didn’t specify all of it I’m the removal request? You ask them for it- but does that allow the PII they sent at that point to be kept? I don’t know!you know why? Because it’s not fucking defined in the law clearly enough. What if they requested removal of data that wasn’t their PII?

Re: UK to depart from GDPR

#557
post #539

Earlier quoted context omitted.

Is that a sarcastic comment? Because GDPR allows for liquidating fines, even for Google. I believe it has a cap of 2% annual global turnover, per infraction, or something similar. Problem is, GDPR is not enforced. I haven't heard of small companies being investigated, let alone having any fines imposed, even when blatantly violating GDPR.

It’s the law, and it places undue burden on small companies that may not have the technical resources to modify their site/apps/data as expected, as many of them contracted out the work initially at great expense. An email address is considered PII, so if users request their data be deleted, the small business is honest and says they can’t, and the user and others raise this to the government, you think that small co…

If a small business cannot delete customer email address from their database, then it does not deserve to survive. It is not a rocket science and it is not unaffordable to have this functionality even in a custom solution.

Re: UK to depart from GDPR

#558
While GDPR's intentions were good, the implementation is hilariously vague/wide and has had a chilling effect on small and large businesses worldwide since going into effect (not to mention the additional costs immediately levied on every business to develop, verify, and maintain GDPR infrastructure).

I'm sure this is a minority opinion on HN but I'm glad to see some countries pulling back, especially in light of recent calls to expand GDPR even further (!).

Re: UK to depart from GDPR

#559

Earlier quoted context omitted.

So you are saying: * A company is holding PII in a system they don't have the resources to manage . * The software is insufficiently secure to hold that data. * The company appears to be even be holding data on people that didn't even do business with the company. * This is in-part caused by the (sub)hiring of companies that also were not scrupulous with PII in the past. You say that this hurts said company, and they…

An email address is PII. Given that many preexisting systems used email addresses as usernames to identify users, let’s say a small business in 2015 hired a company to create a web app which let a user create an account using their email address and it put the email address into a log file with that user’s activity. The contracted developer finished the site, which cost 25000 EUR, much more than the business could af…

So peoples PII should be just sitting there unregulated because companies can't afford to clean up their privacy messes?

Re: UK to depart from GDPR

#560
Just an observation that we seem to have two camps here: one camp correctly noting that GDPR was a net positive for the users, and the other camp correctly noting that GDPR was a net negative for startups and SMBs.

I am surprised that nobody is realizing that what's bad for startups and SMBs is also ultimately bad for the users, just on a longer timescale (with an equally long reversal period).

I remember the US Congress grilling Zuckerberg back in 2018, and him responding that he's certainly willing to make amendments, but if you tie his hands too much, someone from China will swoop in and bypass all regulations. Everyone scoffed at that, and less than 3 years later, TikTok is unstoppable despite Facebook's best efforts. While users' privacy has benefited from Facebook's downfall, their privacy has never been at more risk with the rise of TikTok (I do realize that TikTok's servers are in the US and Singapore, but let's not fool ourselves - the ByteDance leadership would be quickly replaced if they refused a data request from their government). I would consider this a net negative for the users, and particularly for the US as a country.

Just another example proving that the paradox of tolerance [0] is a real thing. If you get too tolerant too quickly, you end up with a less tolerant outcome.

[0] https://en.wikipedia.org/wiki/Paradox_of_tolerance

Post reply on HN