Live data from Hacker News

Statement on 4 Years of GDPR

noyb.eu

181–190 of 195 posts

Re: Statement on 4 Years of GDPR

#181

Earlier quoted context omitted.

One option would be to collect less data on users, which should make it easier to manage.

Easy peasy unless your system was built before it became illegal to "haphazardly" process PII. Even organization that take GDPR very seriously and invest a lot on compliance do not generally really know all the places where their legacy systems are storing PII. The law is draconian.

> Even organization that take GDPR very seriously and invest a lot on compliance do not generally really know all the places where their legacy systems are storing PII. The law is draconian.

I think this is an extremely poor excuse. You're basically saying they don't understand their systems well enough. It is like a chemical company blaming environmental legislation when they've left barrels of polluting chemicals all over the place and not kept track of them.

Re: Statement on 4 Years of GDPR

#182
post #159

We should get to a point where tracking requires users to install an app or a browser extension, I’m thinking of something similar to the ads toolbars of the 90s. I shouldn’t have to tell people I don’t want to be spied, nor I should have to install privacy extensions and PiHoles and whatever.

Isn't this a matter of someone developing a browser that implements this? There are a few privacy focused browsers out there. As long as the most popular browser is developed by the company that benefits the most from tracking, there will always be browser-based tracking.

Re: Statement on 4 Years of GDPR

#183

Earlier quoted context omitted.

https://gdpr.eu/cookies/ Cookie compliance To comply with the regulations governing cookies under the GDPR and the ePrivacy Directive you must: Receive users’ consent before you use any cookies except strictly necessary cookies. Provide accurate and specific information about the data each cookie tracks and its purpose in plain language before consent is received. Document and store consent received from users. Allow…

Cookies aren't part of the GDPR, so they must be part of the ePrivacy Directive. Consent is part of the GDPR, but the way I've seen it operate in practice is widely out of compliance. You're supposed to ask for consent in each specific instance of data collection, not present a blanket approval, and default to "no."

https://gdpr.eu/cookies/

Cookies and the GDPR The General Data Protection Regulation (GDPR) is the most comprehensive data protection legislation that has been passed by any governing body to this point. However, throughout its’ 88 pages, it only mentions cookies directly once, in Recital 30.

Natural persons may be associated with online identifiers provided by their devices, applications, tools and protocols, such as internet protocol addresses, cookie identifiers or other identifiers such as radio frequency identification tags. This may leave traces which, in particular when combined with unique identifiers and other information received by the servers, may be used to create profiles of the natural persons and identify them.

What these two lines are stating is that cookies, insofar as they are used to identify users, qualify as personal data and are therefore subject to the GDPR. Companies do have a right to process their users’ data as long as they receive consent or if they have a legitimate interest.

Re: Statement on 4 Years of GDPR

#184
post #165

Earlier quoted context omitted.

Jurisdiction issues are complex. In this case, the jurisdiction is defined by the location of the customer, not the business. If your business ignores EU courts, that might not have an immediate impact, but in the longer-term, you have a liability if you ever do business in Europe, want to be acquired by someone with a business presence in Europe, and potentially in the future, travel to Europe. GDPR is framed as a h…

Jurisdiction is sometimes complex, but you don't have to be an attorney to see the disconnect in a court in say, Germany, claiming it has jurisdiction over the practices of a food blog run by someone in Kansas because someone in Berlin decided to sign up for their newsletter. I want to be clear I think they have a moral and ethical obligation to delete that person's information if so requested. There's just no (legit…

Western powers did go around and forced various African polities to stop doing slavery under the threat of their cannons...

Re: Statement on 4 Years of GDPR

#185

Earlier quoted context omitted.

GDPR notices are obnoxious, but they are not the only source of popups, not even the most annoying (most of them are converging to standard patterns, so you can dismiss them quickly). These days many sites have a constant barrage of all kind of popups, browser notifications requests, registration nags, adverts and so on, often on a delayed trigger.

> GDPR notices are obnoxious, They're not obnoxious because GDPR made them that way, they're obnoxious because companies who think they have a right to unfettered and undisclosed abuse of people's data (because that's what they were used to) are trying to pretend that the law is the problem and not their malfeasance. A fully compliant GDPR banner has two buttons, of equal prominence: reject all, and accept all. That'…

Of course! I'm just pointing out that getting rid of GDPR wouldn't get rid of the popups.

Re: Statement on 4 Years of GDPR

#186
post #139
post #112

Earlier quoted context omitted.

I think the GDPR is pretty clear: it is illegal to process personal data if you cannot apply an exception listed in the regulation. Also all data that might be deanonymized by some means is personal data. The message is clear: if you put others at risk, you are at risk to get fined. Yes, this makes many, sometimes ideotic things, illegal. But not I also cross a red light on foot from time to time and I do not think i…

> Also all data that might be deanonymized by some means is personal data. One question I've always had with this is whether it counts as personal data if it can only be de-anonymized by combining it with other data. So Company A manages some subset of a person's data.Company B manages a different subset (different app or whatever). Individually it is completely anonymous but if you combine them, it's trivial to de-a…

As far as I understand data can only become anonymous as soon as the part that can lead to reidentification is actually deleted. We have such a case with the release of an 'anonymized' dataset , where the original data or the reidentifying set still exists. As far as I heard the opinions of the DPOs involved, the original data needs to get deleted for the data to be actually anonymous (although the data in the wild will not change). The problem is that otherwise th GDPR would have no effect anymore and the controller could 'anonymize' sensitive information and only keep uncritical identifying information. The other question on what basis of article 6 such processing would be allowed, as also the anonymization proceedure would probably count as processing. However, I have also heard theopinion of DPOs that you do not have to care as a receiver/user about the effectiveness of the anonymization, while other experts clearly state that there is a risk of becoming a controler if you cannot trace the effectiveness of anonymization and even the legal basis for that back to the origin.

Re: Statement on 4 Years of GDPR

#187
post #60

There are signs that it's getting better. I started seeing cookie dialogs with a Reject all button. Sometimes it's a big one, sometimes it's almost white on white, but it's there. Anyway the vast majority of those dialogs is still misleading. The usual We care about your privacy, accept all, settings thing.

This seems to be a very common misconception, but the cookie consent dialogues are not part of GDPR.

They are not required for cookies, but they are required for tracking cookies. If you are only using cookies for e.g. shopping cart or CSRF protection, you don't need a consent dialog, but that is not the case for those websites showing the dialog.

Re: Statement on 4 Years of GDPR

#189

Earlier quoted context omitted.

Easy peasy unless your system was built before it became illegal to "haphazardly" process PII. Even organization that take GDPR very seriously and invest a lot on compliance do not generally really know all the places where their legacy systems are storing PII. The law is draconian.

> Easy peasy unless your system was built before it became illegal to "haphazardly" process PII. - GDPR-like legislation existed in most EU countries waaaaaay before GDPR. - It was known for years that GDPR is coming. - GDPR specifically gave companies two years after going in effect to get their act in order. - We are now 4 years after GDPR went in effect. If you're still complaining that it's "a drakonian law that…

And the watchdogs are helpful. At my previous company, they basically spend 2 man-day (10 hour hands on deck) helping us drafting a compliant architecture document.

Re: Statement on 4 Years of GDPR

#190
post #115

Earlier quoted context omitted.

Wasn’t there recently some ruling against the use of dark patterns in cookie banners?

The big players can afford to pay the fine, and the small ones probably won't be taken to court, so it might not have enough impact.

The potential fines can get pretty enormous, enough to even make the big players worried - up to 4% of the company's global annual revenue. There's a reason Amazon, Google and Facebook haven't just eaten the fines and are paying a fortune fighting tooth and nail to appeal the fines that they've been issued so far.
Post reply on HN