Live data from Hacker News

UK to depart from GDPR

lawgazette.co.uk

631–640 of 659 posts

Re: UK to depart from GDPR

#631
post #619

Earlier quoted context omitted.

So peoples PII should be just sitting there unregulated because companies can't afford to clean up their privacy messes?

You are asking a question as if this was some sort of moral issue, and that's pretty much guaranteed to lead to terrible decisions -- ultimately immoral decisions -- so my advice is to not approach technical problems through a moralistic lense, but through a technical lense. The situation we have now is that massive amounts of code and business processes that were created without the assumption that things like email…

If we consider the consequences of sloppy and/or outright malicious data handling to be negative externalities foisted on society; then removing such externalities by law is pretty much fair game in my opinion.

Especially taking into account that there might not be a linear relationship between the damage accrued by society versus the costs of the company to ameliorate such damage.

Re: UK to depart from GDPR

#632
post #312
post #307

Earlier quoted context omitted.

>> International travel currently banned. > This is the same in many countries, including the UK right now. It isn't really. Many countries barred non-resident non-citizens from entering but only a couple went to the extent of attempting to prohibit their own citizens from leaving . The latter restriction is far more draconian.

> only a couple went to the extent of attempting to prohibit their own citizens from leaving OK then, but the UK is currently one of those places. Without good reason it's currently prohibited. ANd I honestly don't have a problem with it, we're in the midst of a pandemic. :shrug:

I have a problem with it. The definition of "pandemic warranting a lockdown" is a national one, and other countries have a different opinion on it.

By all means, protect your own country by preventing people from going in, but people should be free to leave to a different place with more relaxed rules at their own risk.

Re: UK to depart from GDPR

#633

Can we get a rid of the cookie notifications next? They're so annoying and usually end up conflicting with Adblockers and breaking pages because they're not fully blocked.

The GDPR already forbids consent prompts that are unclear, misleading or designed to annoy the user into submission. A compliant prompt should make it as easy to agree as it is to refuse.

The problem is that the ICO is absolutely incompetent at enforcing it (I found it very funny that the article claims businesses are afraid to use data while in reality not only do they appear to use it just fine and even a bit too much for my liking, but our regulator has only ever handed out 4 fines, all for data breaches and not other abusive usage of data).

Re: UK to depart from GDPR

#634

Just an observation that we seem to have two camps here: one camp correctly noting that GDPR was a net positive for the users, and the other camp correctly noting that GDPR was a net negative for startups and SMBs. I am surprised that nobody is realizing that what's bad for startups and SMBs is also ultimately bad for the users, just on a longer timescale (with an equally long reversal period). I remember the US Cong…

Is there any evidence that TikTok's popularity is due to their non-compliance with regulations, and not just being a novelty and them having lots of money to bankroll such a service without annoying the users with ads like FB does?

Re: UK to depart from GDPR

#635
post #49

Earlier quoted context omitted.

I work in an large euroepan enterprise and our GDPR compliance is... absymal. And we're not even investing that much into becoming more compliant. My impression is that the board is in a state of denial, as doing GDPR properly would probably cost us billions.

Please tell us the name of that European enterprise that breaches the GDPR and we can put the EU enforcement procedures to a test :) Let's call it an experiment..

Google and Facebook's tracking consent flows do not comply with the GDPR.

All the mobile apps that implement tracking & analytics SDK do not comply unless they request explicit consent.

You can start there. The GDPR's spirit is great but the entities tasked with enforcing it are absolutely incompetent.

Re: UK to depart from GDPR

#636

Earlier quoted context omitted.

Right - the law sounds good. But it's not the practice I see on the t'Internet.

Then push it! I've done this before and there are active cases running with the regulatory offices in Germany. It's a slow process for sure but it'll get faster and words will spread, that people are using their rights.

To be fair, the ICO is absolutely incompetent and does not seem to care about enforcing the GDPR. I've reported things much worse than non-compliant consent prompts and the best I got out of them was to send a letter to the organization after months of waiting, which the organization promptly ignored.

Re: UK to depart from GDPR

#637

I'm broadly in favour of any consumer protective legislation like the GDPR, but I feel that the GDPR has been misinterpreted by many, in both directions. Those who ultimately respect user privacy and want to do the right thing are often paralysed by process and making sure that they absolutely can't be sued, rather than being able to show respect for data and best practices but still getting things done. Those who ul…

Yes, there is definitely a lack of enforcement. The annoying consent flows people complain about and blame on the GDPR are actually forbidden by it and news of any enforcement actions would quickly scare most websites into implementing an actually compliant one.

Re: UK to depart from GDPR

#638
post #228

Earlier quoted context omitted.

From my experience, unless I'm missing something, they're annoying because they're not that well implemented, maybe even on purpose? Sites where I have granted access keep asking me to re-grant no matter what. Sites where I have denied do the same (although here I would expect it, not that I agree, since I already clicked "no"). And actually it's cool, sometimes you go to some docs and there's 33 "essential" cookies…

I think you're absolutely right. But I also think it was predictable. If we trusted the companies to do the right thing, we could have done that without GDPR. So OK, they live off advertising, they want to track, so now they just use dark patterns. What's next? Yet more regulations about exactly how to show this fundamentally annoying consent question? I just want to browse the internet!!! Sometimes people talk about…

The GDPR forbids dark patterns and unclear or annoying consent flows. A consent flow that assumes opt-in (pre-ticked checkboxes, etc) or hides the option to opt-out is not compliant.

The problem is the complete lack of enforcement, and the ICO has been particularly incompetent regarding this.

Re: UK to depart from GDPR

#639
post #49

Earlier quoted context omitted.

Please tell us the name of that European enterprise that breaches the GDPR and we can put the EU enforcement procedures to a test :) Let's call it an experiment..

Google and Facebook's tracking consent flows do not comply with the GDPR. All the mobile apps that implement tracking & analytics SDK do not comply unless they request explicit consent. You can start there. The GDPR's spirit is great but the entities tasked with enforcing it are absolutely incompetent.

The thing about enforcing the law is that it's still just politics. You can't suddenly start fining everyone without expecting a backlash. A law only works well when most people are respecting it, not when most people are breaking it.

Re: UK to depart from GDPR

#640
Did anyone actually read the article? Most of the comments here are treating the article as if the UK will depart from GDPR (as the title says) - but the article says nothing of the kind. It will be a slight change, probably reformatted to allow for less red tape and more clarity for small businesses and early-life enterprise. And the UK still needs to keep regulatory alignment to the EU to be able to have low-tarrif access to the markets.

If I was a betting man, I wouldn't bet on this being a significant change, given the world is moving more towards privacy (yes, including US).

Post reply on HN