Live data from Hacker News

UK to depart from GDPR

lawgazette.co.uk

591–600 of 659 posts

Re: UK to depart from GDPR

#591
post #553

Earlier quoted context omitted.

It’s the law, and it places undue burden on small companies that may not have the technical resources to modify their site/apps/data as expected, as many of them contracted out the work initially at great expense. An email address is considered PII, so if users request their data be deleted, the small business is honest and says they can’t, and the user and others raise this to the government, you think that small co…

I think you are describing very hypothetical situations. If you know how to get a company fined, could you please share, so I can report and have action taken against companies that violate and misuse personal data?

Here(1) you have a tracker with (most) fines due to breaking GDPR. In my country there is a local office (all EU states must have one) and all citizens can file online complaints. In 2-3 weeks we get feedback. Real feedback. I have seen electricity companies being fined for sending the electricity bill to the wrong person by e-mail, thereby violating personal info security. It's all on this website.

(1) https://www.enforcementtracker.com/

Re: UK to depart from GDPR

#592

Earlier quoted context omitted.

The pop ups are not usually complaint though. So its not that the execution was poor, but rather that the enforcement is poor. Also, your Twitter quote shows another issue: conflating GDPR with the Cookie directive. They are two very different laws. GDPR is concerned with personally identifiable data and data protection, the cookie laws are concerned with tracking users online. GDPR applies to all data (not just webs…

Ok thanks for the clarification. Twitter are specifically saying that they’re going to use cookies for a bunch of things there that are not necessary - like ads. So how is that allowed?

Its not, unfortunately enforcement is... seriously lacking.

Re: UK to depart from GDPR

#593

Earlier quoted context omitted.

That's not true unfortunately. It has a blanket exception for anything remotely government related (meaning government itself and anyone the government authorizes), and in fact guarantees far more and wider access to your most sensitive data, not less. And it allows the government to authorize whoever they please to not just keep more data about you, tighter and more closely linked together, but to keep this from you…

I've never heard this criticism of GDPR before, and a couple of cursory Google searches didn't yield anything supporting what you're claiming. Do you have a source for that?

In English, for example:

https://ico.org.uk/for-organisations/guide-to-data-protectio...

As for the "you can't get data removed or even access it", here's some specific examples:

https://ico.org.uk/for-organisations/guide-to-data-protectio...

https://ico.org.uk/for-organisations/guide-to-data-protectio...

Like everywhere else, medical and "social work" data (and keep in mind that both the medical and social workers can lock people up for extended periods of time, even in isolation. Extended means decades, even until death, and that under circumstances that are justified using records on which that applies. You can't access, remove or change that data, but it can (and is in practice) used to lock you away legally indefinitely)

Insurance:

https://ico.org.uk/for-organisations/guide-to-data-protectio... (NHS is the insurer in Scotland. Essentially, ANY data that can be used for legal purposes (whether to sue you or to defend itself or any decision it made) is exempt from GPDR. No matter how personal the data. Technically this may even cover publishing such data.

I realize this is for one specific part of Europe, but there are analogues everywhere. And, frankly, look at the size of that list. It's only the beginning, on the left, click open, "right to X" and there's yet another list of exemptions.

Re: UK to depart from GDPR

#594

Earlier quoted context omitted.

Corruption might be the wrong word. But 'disagree politically' suggests that what voters think matters, instead of what financial contributors desire. Every political decision has winners and losers. This one seems heavily biased towards the 0.01% of people directly financially incentivized, while the rest has to deal with the breach of privacy and the social effects of hyper targeted advertisement ( a case can be ma…

I disagree. Most startups and other small businesses, for example, are not run by the 0.01%. And yet, the data ecosystem is often key to their success. Targeted ads are a boon to hairdressers and multi-billion-dollar conglomerates alike. Just because something happens to enrich the top end, doesn't mean it's of no use to everyone else. We shouldn't avoid doing overall beneficial things because the rich will tend to b…

> Targeted ads are a boon to hairdressers

Are they? Are targeted ads really increasing the number of hairdressers and/or making them more profitable?

Re: UK to depart from GDPR

#595

Earlier quoted context omitted.

Most of these companies wouldn't know how to make much use of the data anyway. My experience working with companies and analytics (even did an analytics startup some years back) is that they haven't a clue about how to actually use it and just heard that more data is somehow better. That to me sounds like they're most likely to sell the data, since they don't know how to use it themselves. Better these companies have…

Companies still need some basic data for whatever problem they're solving, right? As an example, let's say I want to launch a blogging platform. You need some basic tables (data) like User, Posts, Tags, etc. I'd consider this data the business needs for core business. Does there need to be some GDPR compliance thing? Anecdotally a dumb app I built I was worried about EU visitors and just wanted to block them instead…

> Does there need to be some GDPR compliance thing?

Yes. GDPR is about data protection. If you want to do business in its jurisdiction, then you need to know the laws.

In general, GDPR states that you cannot store anything that isn't strictly necessary, unless you outline what you want to collect and what it will be used for in your data policies. You are not allowed to use it for anything else and once its no longer needed for the outlined use, it must be removed. Personally identifiable information has some additional rules (and its important to note that anything could become PII if combined with something else, that would, together, allow for someone to be identified).

My own (EU-based) country's data protection websites states:

1. Everyone has the right to the protection of personal data concerning him or her.

2. Such data must be processed fairly for specified purposes and on the basis of the consent of the person concerned, or some other legitimate basis laid down by law.

3. Everyone has the right of access to data which has been collected concerning him or her, and the right to have it rectified.

4. Compliance with these rules shall be subject to control by an independent authority.

This means that every individual is entitled to have their personal information protected, used in a fair and legal way, and made available to them when they ask for a copy. If an individual feels that their personal information is wrong, they are entitled to ask for that information to be corrected.

Re: UK to depart from GDPR

#596
post #581
post #490

Earlier quoted context omitted.

Gdpr means you need to have a disagree button. Just click it for everything

(a) not everyone has a disagree button today (b) many people make the disagree button small, hard to see, or require clicking through multiple screens to get to GDPR really should have dictated "agree" and "disagree" be of equal visual weight and button styling and dictated disagreeing to be a 1-click action.

GDPR doesn't dictate anything about styling or anything, it just says you have to ask for consent, you're not allowed to bundle consent with anything else (eg you can't say that I have to give consent for me to be able to use the site) and IIRC it does even have a clause about consent having to be asked for in a clear understandable form.

I'm pretty sure that everyone doing our (b) is not compliant at all. The problem is that GDPR isn't being enforced very well.

Re: UK to depart from GDPR

#597

Earlier quoted context omitted.

Are you in the EU? I'm a developer in the EU and that is patently not true. Developers have to have mechanisms in place to delete gdpr data when required and not store data that's not required for you goals. In my experience gdpr puts a real and meaningful curb on the strong impetus to gather everything and sell it.

> Developers have to have mechanisms in place to delete gdpr data when required and not store data that's not required for you goals Purely anecdote, but zero companies I know in Germany, Italy or France are doing this. (The ones in Switzerland are.) There is a cosmetic fix that produces an email so there is something to show a regulator if they come knocking. The logic being investing anything more than that is a cr…

Also pure anecdotal, I have had GDPR interactions with EPIC Games (asked them to delete my account) and Blizzard Entertainment (asked them to retrieve my data). Both went well. The interaction with EPIC was manual, I had to send an email and got back what it looked like a personalized e-mail. Account seemed to be deleted.

With Blizzard it went a bit different. They do have online automated tool to download your own data, but with a twist: they refused to provide what they consider security risk information. They did provide a lot of data (even years old chat logs) but did not provide the information I was looking for: list of processes running on my PC, which they scan periodically, as an anti-cheating mechanism. I went further and filed a GDPR infringement complaint to the national office but it failed. Last option was to sue, but I gave up.

Both Epic and Blizzard are US based.

Re: UK to depart from GDPR

#598
post #115

‘too many businesses and organisations are reluctant to use data – either because they don’t understand the rules or are afraid of inadvertently breaking them’ TBH I'm glad companies stay away from my data if they don't know how to get consent, store data securely, or even what those things mean.

For cases like this I think consistent enforcement is the most important thing.

In the short term it may sound great that a lot of companies are erring on the side of caution and not using the data, when perhaps they could.

But if there's no enforcement this gives a huge competitive advantage to companies who just don't care at all. They might crowd out the former set. If such companies were not erring on the side of caution, and using some data in a natural way like they used to rather than avoiding it like the plague, they may provide competitive pressure against this dishonest set.

It is a lot like paying taxes. If I am an honest small business owner who pays my taxes but my competitors in the field are known for underhanded cash schemes that dodge tax, I'm not going to last long. I need the law to go after them or I'm done unless I start playing the same game. After dabbling in a small business compliance can be a real killer and it's my honest opinion a lot of people just play it dumb except where they know it matters, and hope for the best.

Re: UK to depart from GDPR

#599

Earlier quoted context omitted.

I grew up in the city in Australia. Once when I crossed the road (as a pedestrian) at a red light, a police officer on the other side of the street stopped me and gave me a warning for jaywalking. Before I had walked, I had looked both ways and deemed it safe; there was no traffic and no other pedestrians waiting. (In my mind: I am just a person on planet Earth, trying to get from position A to position B, less than…

As someone who was doing the other way around (hey dan!) working in australia coming from france i always find it weird how australian could accepts almost everything from the government with not much contestation, I remember when there was a law who passed thru in Australia where every small company could fire anyone on the day (it wasn't the case before, i think there was a 3 month period or something). The law pas…

Australia is very apathetic in general. "She'll be right" is basically our national motto and while it can be good for overcoming external adversity and natural disasters, I don't think it's serving us too well when dealing with internal human and political factors.

Re: UK to depart from GDPR

#600

Earlier quoted context omitted.

"DIY (do it yourself) electrical work is dangerous and illegal." https://www.nsw.gov.au/topics/electrical-safety/in-the-home#... Arduino is fine. > This is the same in many countries, including the UK right now. Yes, true in UK during the past 1-2 months of national lockdown? Aus's has been the case for 12 months.

This page is tragically funny. It ends with 'You should never attempt to carry out any electrical maintenance other than changing a light globe.'

There was (is?) a rumour that changing light globes was technically illegal under the letter of the law in Victoria. A quick search shows this may have been a 1998 law amended in 1999. Either way, people believed it which says something.
Post reply on HN