Live data from Hacker News

You Know GDPR Is Good Based on Who Hates It

matduggan.com

121–130 of 180 posts

Re: You Know GDPR Is Good Based on Who Hates It

#121
post #15

Earlier quoted context omitted.

They do come from the ePrivacy directive but; > if you want to store data on the user's browser you do need to get their consent, hence the cookie banner. No - you need consent for storing cookies that are not “strictly necessary”. I can implement an offline app that stores data in cookies without consent. The current usage of the banner is overly litigious US focused simplification combined with malicious compliance…

No cookie is strictly necessary, you can encode it all into request tokens in the URL, so this is a meaningless exception.

So you’re saying if I log into HN, every intra-site link should be rendered with “?token=” and if I send a link to a friend it will let them be logged in as me?

No, because that would be ludicrous, cookies are obviously necessary for the concept of a “login” or even just a “session” to exist.

Re: You Know GDPR Is Good Based on Who Hates It

#122
post #68

Earlier quoted context omitted.

[flagged]

Meta, but what’s the point of engaging in a discussion forum and writing a comment only to back out of actually discussing the points you disagree with?

That’s what OP did. "Again, not some weird controversial point." OP already declared their statements as axioms.

Re: You Know GDPR Is Good Based on Who Hates It

#123

there is a whole campaign online about hating on the EU & its regulations.

I'm a European citizen. I hate the EU.

Europeans were blowing each other up 80 years ago. Now we have complete freedom of movement and trade. You're missing the forest for the trees. The EU is the greatest achievement of our parents' generation.

Re: You Know GDPR Is Good Based on Who Hates It

#124
post #89
post #68

Earlier quoted context omitted.

Meta, but what’s the point of engaging in a discussion forum and writing a comment only to back out of actually discussing the points you disagree with?

It's a social manoeuvre, the idea is basically like standing up and clapping to show support. For example, maybe someone wants to support/oppose a position but is genuinely not the sort of person who believes in making an argument. From that perspective a little public "I disagree and question your character" post is an obvious tactic. The idea isn't to make a point so there isn't normally much reason to respond.

The idea is to make people think about what they say, and maybe not declare themselves the winner in advance. Kinda like you do by declaring what my intentions were.

Re: You Know GDPR Is Good Based on Who Hates It

#125

Earlier quoted context omitted.

You do need consent even for the necessary exemption in practice because of how that is defined; the user must have explicitly asked for the function that requires the cookie: > strictly necessary in order for the provider of an information society service *explicitly requested* by the subscriber or user to provide the service. But this the basis for the OK-only style of banner, to inform the user that certain functi…

If you're in a shopping site and "add to basket" -- explicity requested. If each page you browse on the shopping site shows what's currently in your basket -- explicitly requested. If you checkout and get a list of what's in the basket and give you card details for payment and email for receipt -- explicitly requested. No consent needed. On the other hand, deliberately analysing log data after the fact for which prod…

Dropping permanent cookies for any of this stuff is not strictly necessary; session cookies would be sufficient, so then to do anything convenient (e.g. persistent cart, Amazon-style) but not necessary you still need to request consent.

GDPR's legitimate interest basis is better written. But ePD is not superceded by GDPR, they are layered on top of each other.

Re: You Know GDPR Is Good Based on Who Hates It

#126

GDPR itself is quite a good law. It's implementation and enforcement are not. E.g. the nag problem would have been solved simply and effectively with something like do-not-track header (probably as OS setting, as apps are often even worse than websites with tracking). Also enforcement of obvious violations taking years and years, especially against large corporations, means it's just violated all the time. EU also fa…

> the nag problem would have been solved simply and effectively with something like do-not-track header

You’ll be glad to know that the EU is working on a proposal to do just that. Look for EU Digital Omnibus article 88b.

You’ll also be unsurprised to know that companies like Google are already lobbying hard to prevent it.

Re: You Know GDPR Is Good Based on Who Hates It

#127

I worked in a small startup in Berlin and I remember we used to have a person dedicated to handle GDPR stuff. She had to go to Berlin data authority periodically and report status. I was really surprised given how small the company was, why we needed a dedicated person to handle all the bureaucracy. Apparently it was the law. Also with the new package law in EU. I believe all these laws are how EU creates employment…

> She had to go to Berlin data authority periodically and report status.

That seems more of a German bureaucracy thing rather than GDPR specifically.

The UK, which does still implement GDPR from its time as a member state, does not require this level of officiousness.

Re: You Know GDPR Is Good Based on Who Hates It

#128
post #110

Earlier quoted context omitted.

I dunno, recently traveling through Europe I mentally “joined” the campaign by seeing the ridiculousness for myself. I very much support their ideals and their people-centered mindset. But in execution it’s that meme: US rocket lands in slow motion on reusable pad, Chinese rocket lands in slow motion on reusable pad, European hand in slow motion closes a water bottle cap that is permanently attached to the bottle and…

> But in execution it’s that meme: (…) If you agree with that meme, you’ve fallen for the manipulative narrative of lobbyists¹. Bottle caps are a massive problem (as is plastic in general) on the environment (you know, the thing we all live in) and the regulation is already having an impact. There will be more regulating the uses of plastic. If you don’t know why the bottle caps are so problematic, you live a privile…

I've had the bottle cap in my nose multiple times... nobody's tricking me into not liking it.

Yes: I have the privilege of living in a developed 21st century world where I don't need to deal with stuff like this. Proud of it.

I'm well past being told to eat my vegetables because children in Africa are starving.

The solution is to expand the pie for everybody, not to throw our arms up and return to living in caves in harmony with "nature". Technology and progress solve this.

Re: You Know GDPR Is Good Based on Who Hates It

#129
post #114
post #84

Earlier quoted context omitted.

I think GDPR is more good than bad, but the author's example of surveillance capitalism is easily repeated on most EU news sites. Visit bild.de and watch the network inspector light up like a christmas tree. Do you really feel your privacy is being respected? The 996 partners banner is just the piss take that supposedly makes this legal.

So why is it good if it does nothing? This is where you should apply eng principles. If something adds complexity without solving a problem, start by removing the complexity rather than tweaking

It did nothing for ad tech crap yet, but it gives you many easily exercised rights to access and erase your data. An American company "OpenAI" has released a very useful human-EU bureaucrat-translation tool for drafting such requests.

Re: You Know GDPR Is Good Based on Who Hates It

#130
post #97

Earlier quoted context omitted.

You don’t need to hire such a person since you’re way too small for the thresholds. And besides, if you’re unable to accept that you have a social responsibility when you run a business, I don’t know what to tell you? You also have to keep up with other regulations; that’s the price of doing business. And the churn you’re talking about is way less than you make it to be; it’s not like there is change every month. We…

> You don’t need to hire such a person since you’re way too small for the thresholds > You also have to keep up with other regulations; that’s the price of doing business Which one is it then? As small business I am suppose to follow all that ethical regulation bs, the same way as large company, without hiring extra peolle? But I should do it unpaid, in my free time (sleep less, or quit day job)? Keep on mind I get l…

> Which one is it then?

You don’t need a dedicated data protection officer, because your company is too small for that. You also don’t have to abide by lots of regulations that only apply to bigger businesses. But you still need to comply with the basic requirements, and that is your job as a business owner. I know what I am talking about, because this is part of my job. So unpaid doesn’t really match the reality here, right? Or do you consider filing your taxes as unpaid regulatory bullshit work too?

> Keep on mind I get lower salary than garbage man!

It doesn’t sound like your business is very worthwhile of keeping up, then? I don’t say this in spite, but if you don’t have a reasonably good income from your company, why do you put up with all the hassle in the first place..?

> I do not "store data",.

Sure you do, if you sell anything. You need to know where to ship stuff, customers contact you, pay you, all that. And as your customer, I don’t want you to store that longer than necessary or sell it to someone else.

Post reply on HN