Live data from Hacker News

Statement on 4 Years of GDPR

noyb.eu

161–170 of 195 posts

Re: Statement on 4 Years of GDPR

#161
post #141

I don't think the law has done much at all. I operate a business that serves as a data broker / processor under GDPR. I have had a total of 66 data requests in 4 years. I handle data requests and follow the laws, but I also understand the EU/UK has zero grounds to enforce anything against my business if I were to flat out reject all requests. They can't fine me, I don't have a physical or business presence in Europe,…

This is an admirable position, and one of my biggest problems with GDPR. Honestly, my only problem with it. The EU does not have the legal jurisdiction to tell any company based outside of the EU what to do with its data, whether that data is about EU citizens or not. If I ran a SaaS I would probably do the same thing as you (out of respect for my customers) but I certainly wouldn't feel any legal compulsion to do so…

Is that really true? My understanding for example in the USA is that if you violate the laws in another country, you automatically violate the laws in the USA (under the Foreign Corrupt Practices Act - https://www.justice.gov/criminal-fraud/foreign-corrupt-pract...) - or is that really just limited to bribery? AFAIK some other countries have similar provisions.

Re: Statement on 4 Years of GDPR

#162

Earlier quoted context omitted.

One option would be to collect less data on users, which should make it easier to manage.

Easy peasy unless your system was built before it became illegal to "haphazardly" process PII. Even organization that take GDPR very seriously and invest a lot on compliance do not generally really know all the places where their legacy systems are storing PII. The law is draconian.

If you are found in breach, the regulator would approach you in good faith and assuming you are in good faith. You will be given time to fix your systems and the regulator would allow some back and forth to get to the right result.

In order to get a fine you have to act evidently in bad faith or to lose your users’ PII or credit card information.

People don’t get fined billions because a legacy system saves an email address in the wrong table.

Re: Statement on 4 Years of GDPR

#163
post #141

I don't think the law has done much at all. I operate a business that serves as a data broker / processor under GDPR. I have had a total of 66 data requests in 4 years. I handle data requests and follow the laws, but I also understand the EU/UK has zero grounds to enforce anything against my business if I were to flat out reject all requests. They can't fine me, I don't have a physical or business presence in Europe,…

This is an admirable position, and one of my biggest problems with GDPR. Honestly, my only problem with it. The EU does not have the legal jurisdiction to tell any company based outside of the EU what to do with its data, whether that data is about EU citizens or not. If I ran a SaaS I would probably do the same thing as you (out of respect for my customers) but I certainly wouldn't feel any legal compulsion to do so…

Jurisdiction issues are complex. In this case, the jurisdiction is defined by the location of the customer, not the business.

If your business ignores EU courts, that might not have an immediate impact, but in the longer-term, you have a liability if you ever do business in Europe, want to be acquired by someone with a business presence in Europe, and potentially in the future, travel to Europe.

GDPR is framed as a human rights law, and that has long-reaching claws.

It is currently not well-enforced, but there are many examples of clawbacks coming in. For US slavery, those clawbacks are coming 160 years later: buildings, businesses, and schools are being renamed. Statues are being torn down. In some cases, you're starting to see reparations (see Harvard). Milder versions of racism are subject to cancellations; things acceptable in 1980 are having repercussions on people's careers in 2020.

Then you've got issues of when you're persecuted for an unrelated reason, and the government is looking for an excuse or pretext to take you down. A famous mobster was taken down a century ago for tax evasion.

Re: Statement on 4 Years of GDPR

#164
post #60

There are signs that it's getting better. I started seeing cookie dialogs with a Reject all button. Sometimes it's a big one, sometimes it's almost white on white, but it's there. Anyway the vast majority of those dialogs is still misleading. The usual We care about your privacy, accept all, settings thing.

"Better" would mean not seeing cookie dialogs at all.

The EU's ePrivacy Regulation[1] has (or had - it seems to fluctuate) a goal to move cookie consent into the user's browser settings.

There has (perhaps predictably) been significant lobbying against that by entrenched industry players, so we'll see what emerges as a result.

(I have to admit I'm not up-to-date on the latest happenings regarding this regulation)

[1] - https://en.wikipedia.org/wiki/EPrivacy_Regulation

Re: Statement on 4 Years of GDPR

#165
post #141

Earlier quoted context omitted.

This is an admirable position, and one of my biggest problems with GDPR. Honestly, my only problem with it. The EU does not have the legal jurisdiction to tell any company based outside of the EU what to do with its data, whether that data is about EU citizens or not. If I ran a SaaS I would probably do the same thing as you (out of respect for my customers) but I certainly wouldn't feel any legal compulsion to do so…

Jurisdiction issues are complex. In this case, the jurisdiction is defined by the location of the customer, not the business. If your business ignores EU courts, that might not have an immediate impact, but in the longer-term, you have a liability if you ever do business in Europe, want to be acquired by someone with a business presence in Europe, and potentially in the future, travel to Europe. GDPR is framed as a h…

Jurisdiction is sometimes complex, but you don't have to be an attorney to see the disconnect in a court in say, Germany, claiming it has jurisdiction over the practices of a food blog run by someone in Kansas because someone in Berlin decided to sign up for their newsletter.

I want to be clear I think they have a moral and ethical obligation to delete that person's information if so requested. There's just no (legitimate) legal requirement. The huge jurisdictional overreach by GDPR is part of why you're seeing companies just outright ignore parts of it.

Reasonable people can disagree about whether or not GDPR actually covers anything in the spectrum of "human rights" but for the love of god slavery has nothing to do with anything about it.

Re: Statement on 4 Years of GDPR

#166
post #141

Earlier quoted context omitted.

This is an admirable position, and one of my biggest problems with GDPR. Honestly, my only problem with it. The EU does not have the legal jurisdiction to tell any company based outside of the EU what to do with its data, whether that data is about EU citizens or not. If I ran a SaaS I would probably do the same thing as you (out of respect for my customers) but I certainly wouldn't feel any legal compulsion to do so…

Is that really true? My understanding for example in the USA is that if you violate the laws in another country, you automatically violate the laws in the USA (under the Foreign Corrupt Practices Act - https://www.justice.gov/criminal-fraud/foreign-corrupt-pract... ) - or is that really just limited to bribery? AFAIK some other countries have similar provisions.

The FCPA is incredibly specific.

What US law requires a US citizen to comply with EU law?

Re: Statement on 4 Years of GDPR

#167

Earlier quoted context omitted.

This seems to be a very common misconception, but the cookie consent dialogues are not part of GDPR.

https://gdpr.eu/cookies/ Cookie compliance To comply with the regulations governing cookies under the GDPR and the ePrivacy Directive you must: Receive users’ consent before you use any cookies except strictly necessary cookies. Provide accurate and specific information about the data each cookie tracks and its purpose in plain language before consent is received. Document and store consent received from users. Allow…

Cookies aren't part of the GDPR, so they must be part of the ePrivacy Directive.

Consent is part of the GDPR, but the way I've seen it operate in practice is widely out of compliance. You're supposed to ask for consent in each specific instance of data collection, not present a blanket approval, and default to "no."

Re: Statement on 4 Years of GDPR

#168
post #136

I completely reject the premise of this, that one is somehow EU citizens are not personally responsible for the information they themselves put online. The most hilarious thing is cookies! For example, cookies exist, and they work a certain way... and despite not liking how they work.. they are here, and not going away, and imposing some kind of contract-law of cookies being accepted or rejected totally ignores that…

The idea of cookies was to establish sessions - something which can be done by other means, so cookies aren't needed. It would be good to have browsers which would clean all cookies every browser restart. Not enough though, some browser sessions can last months, so a better solution is needed.

I don't know of another way that reaches the same security model as secure httpOnly cookies, which are the recommended way to do session cookies.

Re: Statement on 4 Years of GDPR

#170
post #164

Earlier quoted context omitted.

"Better" would mean not seeing cookie dialogs at all.

The EU's ePrivacy Regulation[1] has (or had - it seems to fluctuate) a goal to move cookie consent into the user's browser settings. There has (perhaps predictably) been significant lobbying against that by entrenched industry players, so we'll see what emerges as a result. (I have to admit I'm not up-to-date on the latest happenings regarding this regulation) [1] - https://en.wikipedia.org/wiki/EPrivacy_Regulation

I meant not bothering with it at all. I, and many others, don't care about cookie tracking. These "cookie warnings" waste users' time, and, to a lesser extent, developer time (but at least we get paid to implement pointless stuff.) Every time I see one of those pop ups, it raises my blood pressure.
Post reply on HN