Live data from Hacker News

UK to depart from GDPR

lawgazette.co.uk

621–630 of 659 posts

Re: UK to depart from GDPR

#621
post #597

Earlier quoted context omitted.

> Developers have to have mechanisms in place to delete gdpr data when required and not store data that's not required for you goals Purely anecdote, but zero companies I know in Germany, Italy or France are doing this. (The ones in Switzerland are.) There is a cosmetic fix that produces an email so there is something to show a regulator if they come knocking. The logic being investing anything more than that is a cr…

Also pure anecdotal, I have had GDPR interactions with EPIC Games (asked them to delete my account) and Blizzard Entertainment (asked them to retrieve my data). Both went well. The interaction with EPIC was manual, I had to send an email and got back what it looked like a personalized e-mail. Account seemed to be deleted. With Blizzard it went a bit different. They do have online automated tool to download your own d…

[deleted]

Re: UK to depart from GDPR

#622
post #258

Earlier quoted context omitted.

> OK, so the problem is that I find it basically impossible to understand how a well-informed and rational person could come to the conclusions you've come to. That is indeed a problem, but it is your problem. If 48% of people support anything , there must be some reasons for it. You're right about the consensus among economists. At the same time, 10 years ago there was a consensus about the virtues of free trade. Th…

>You're right about the consensus among economists. At the same time, 10 years ago there was a consensus about the virtues of free trade. Then Autor et al. wrote "The China Shock" and other similar papers, and, well, now there's not a consensus any more. Also, economics isn't immune to bias. Are papers showing a link from immigration to low wages, or crime, or reduced trust, likely to get a fair hearing? Physical rea…

"I think you'll find it's a bit more complicated than that."

One particular reason: while trade increases welfare, it also has distributional effects. As trade barriers go to zero, the marginal effect on welfare of a further reduction becomes small, compared to the marginal effect on distribution.

Another reason: globalization allows capital to avoid restrictions (e.g. on environmental externalities, child labour, slavery) that are seen in the West as part of the social contract.

Here's the Autor paper: https://www.nber.org/system/files/working_papers/w18054/w180...

Dani Rodrik's recent work on populism: https://www.nber.org/system/files/working_papers/w23559/w235...

And his classic "Has globalization gone too far" is worth reading too.

Re: UK to depart from GDPR

#623
post #597

Earlier quoted context omitted.

Also pure anecdotal, I have had GDPR interactions with EPIC Games (asked them to delete my account) and Blizzard Entertainment (asked them to retrieve my data). Both went well. The interaction with EPIC was manual, I had to send an email and got back what it looked like a personalized e-mail. Account seemed to be deleted. With Blizzard it went a bit different. They do have online automated tool to download your own d…

Why did it fail,may I ask? Epic and Blizzard are US based but do significant business in the EU, so lots of stuff would apply to them.

It failed because, based on the evidence I have submitted to the national authority for data protection (the national entity enforcing the gdpr), they were not able to rule in my favor. In the e-mail exchange between me and Blizzard, they declared they store process data anonymized, but I don't believe it, since based on that data they decide to ban real game accounts (which are linked to real personal data). Going to trial just to try to prove a point wasn't worth it for me, but at least I have seen the national authority for data protection actualy reading the documents I have submitted, fundamenting their ruling with quotes from them.

Re: UK to depart from GDPR

#624

I have mixed feelings about this. On the one hand, I think GDPR is a great step towards stopping companies hoarding your data and holding you hostage to it. On the other, main GDPR change is those awful 'hand over data / pretend you're not' dialogue boxes. When I'm feeling strong, I look for the 'reject / object / blah' box, but often I don't find it in me to resist anymore. So maybe it's not awful they're reshaping…

The GDPR sets a pretty straight border for this. No active (this does NOT include "by using this site you accept...") approval = no permission to collect data and give it to third parties. That's the law. But we'll still need some hard work and hefty fines to make everyone obey it.

Yeah. For now it's more of a latent danger than a law that is enforced according to its spirit or even letter - the letter of the law is fairly clear. I hope and assume that it will be enforced as soon as someone in the right position takes an interest in it.

Re: UK to depart from GDPR

#625
post #497

Earlier quoted context omitted.

Did you read the law and then work on complying with it? Spirit of the law is great. Implementation and end result is a typical bureaucracy mess, with not much benefit for end user, that functions mostly as a way for government to have a leverage over companies for non-compliance, whenever they want to put pressure on them.

While there are byzantine parts, I think it has been a net positive for the user. People focus mostly on the cookie popups, but forcing companies to delete data after the user stopped using the service for too long, or even giving a legal stand on users requesting their data to be deleted wouldn’t have happened any other way I think. In a lot of european countries GDPR came on top of other existing customer protectio…

Add to that the ability to download you own data, so that it isn't held hostage by companies.

Re: UK to depart from GDPR

#626
post #563

Earlier quoted context omitted.

That's why the first line of remedy is to help the company achieve compliance. Good faith on the part of the company goes a long way too. The law is not like code. Thank god.

Law is not like code but the GDPR is so vague and open to interpretation that it gives almost no real guidance and instead puts you at the whims of whatever the current enforcer thinks.

GDPR has been in place for years now, why are people still spreading this narrative that it's super complex and dangerous for every company?

Where are the examples of companies following the spirit of it getting punished regardless?

Re: UK to depart from GDPR

#627
post #115

‘too many businesses and organisations are reluctant to use data – either because they don’t understand the rules or are afraid of inadvertently breaking them’ TBH I'm glad companies stay away from my data if they don't know how to get consent, store data securely, or even what those things mean.

TBH I'm glad companies stay away from my data if they don't know how to get consent, store data securely, or even what those things mean. “Storing data securely” and “getting consent” are both wildly different from full compliance with the onerous requirements of GDPR. You can do both of these things in absolute good faith and still be in violation. Unless you have a team of legal scholars working for you, odds are t…

> That is why the UK is abandoning it. GDPR, as written, is a business-killing mess.

GDPR has been in place for years, which businesses has it killed?

Do you have an example of a company that you consider was not doing anything wrong in your personal opinion but still got a GDPR fine?

Re: UK to depart from GDPR

#628

Earlier quoted context omitted.

This is an illusion, only thing that happened is that you only get access to websites if you give away your GDPR consent. I love the ignorance of people over here thinking that GDPR is nothing more than just that accept button that people click in order to get access to the websites.

At least in SAP (german softwarecompany 100.000 employees) we have to follow gdrp very stricktly and we do. I don't know if that was the case before gdrp but we have to centraly clarify if and when we store user data, what we do with it and we have to show that we can delete user data if requested. Not sure how far small companies go through this thow.

SAP makes mega-customizable software installed at thousands of large companies, it's probably on the extreme end of the difficulty spectrum when it comes to complying with GDPR.

Re: UK to depart from GDPR

#629
post #464

Earlier quoted context omitted.

It feels good to not agree successfully in the lack of a "I don't agree" button. I block their cookies anyway. :) I need to find better ways to mess with their fingerprinting though, or maybe throw back some bogus cookies at them with badly-formatted data instead of blocking them.

Is this something people do? Is it possible for a user to edit a cookie in a malicious way? Do servers typically trust cookies they have placed on a user's machine?

> Is it possible for a user to edit a cookie in a malicious way?

Obviously, it comes from the user's machine so it can be modified before being sent to the server. Unless you're doing something custom/fancy like signing that data you shouldn't trust that it hasn't been tampered with.

Re: UK to depart from GDPR

#630
post #626

Earlier quoted context omitted.

Law is not like code but the GDPR is so vague and open to interpretation that it gives almost no real guidance and instead puts you at the whims of whatever the current enforcer thinks.

GDPR has been in place for years now, why are people still spreading this narrative that it's super complex and dangerous for every company? Where are the examples of companies following the spirit of it getting punished regardless?

Enforcement has been light. Companies are still living in fear of an uncertain regime that means whatever the government body accusing you of violating says it means. A primary function of law is to give you certainty of your obligations.
Post reply on HN