Live data from Hacker News

You Know GDPR Is Good Based on Who Hates It

matduggan.com

131–140 of 179 posts

Re: You Know GDPR Is Good Based on Who Hates It

#131

there is a whole campaign online about hating on the EU & its regulations.

People are hating it untill goes abroad to the countries where no such regulations exists. Like in Switzerland it's okay to charge double for the car insurance simply because you carry "unlucky" citizenship. Or EU law about mandatory 14-day return policy for internet order. Ordered recently something in Switzerland and turns out it was a special sale where standard rules does not apply and items could not be returned…

You're right that the EU has much stricter baseline consumer protections than Switzerland, but none of the examples you gave are actually part of the GDPR. Insurance pricing rules come from EU equal treatment directives, the 14-day online return window is the EU Consumer Rights Directive, and the USB-C mandate is the Common Charger Directive (which Switzerland actually adopted into law in 2024 anyway).

The GDPR is strictly about data privacy, and it deserves defense on its real merits: it made data collection illegal by default without an explicit legal basis, banned deceptive tracking patterns, and introduced turnover-based fines large enough that tech companies actually had to re-engineer their systems around privacy by design. EU consumer protection directives are great, but it's worth crediting the right ones.

Re: You Know GDPR Is Good Based on Who Hates It

#132
post #15

Earlier quoted context omitted.

The cookie banners come from the earlier ePrivacy Directive, and while it was possible to comply by not storing cookies at all, if you want to store data on the user's browser you do need to get their consent, hence the cookie banner.

They do come from the ePrivacy directive but; > if you want to store data on the user's browser you do need to get their consent, hence the cookie banner. No - you need consent for storing cookies that are not “strictly necessary”. I can implement an offline app that stores data in cookies without consent. The current usage of the banner is overly litigious US focused simplification combined with malicious compliance…

Do you have an example of a maliciously-complying website? Virtually all remotely popular websites deliberately use unnecessary cookies.

Re: You Know GDPR Is Good Based on Who Hates It

#133
post #130

Earlier quoted context omitted.

> You don’t need to hire such a person since you’re way too small for the thresholds > You also have to keep up with other regulations; that’s the price of doing business Which one is it then? As small business I am suppose to follow all that ethical regulation bs, the same way as large company, without hiring extra peolle? But I should do it unpaid, in my free time (sleep less, or quit day job)? Keep on mind I get l…

> Which one is it then? You don’t need a dedicated data protection officer, because your company is too small for that. You also don’t have to abide by lots of regulations that only apply to bigger businesses. But you still need to comply with the basic requirements, and that is your job as a business owner. I know what I am talking about, because this is part of my job. So unpaid doesn’t really match the reality her…

> You don’t need a dedicated data protection officer, because your company is too small for that.

But I do need dedicated comliance officer! The lower thresholds applies from 250 employees. I still have the same obligations as larger companies!

And if do notmp comoly goverment will fine me to oblivion!

> So unpaid doesn’t really match the reality here, right?

It absolutely matches the reality. You expect me to do stuff for free. Or can I demand extra money to match minimal salary on my tax return?

Luckily AI can now automate this shit, so now I spend cents instead of dozens hours of labour!

> It doesn’t sound like your business is very worthwhile of keeping up, then? I don’t say this in spite,

Because I have social responsibility to make some rare stuff available, as you would put it! But EU is not making it any easier!

> If you indeed do end up with authorities auditing your business, they absolutely value if you’ve tried your best

So at end I should hope for the best right and relly on merci? My gov just loves to skull fuck "capitalists"!

Re: You Know GDPR Is Good Based on Who Hates It

#134
I don't quite understand GDPR though as it theoretically let's me remove my personal data from benign websites, but doesn't let me remove my data where I would really want it removed, e.g. (my personal nemesis) SCHUFA, CRIF, Boniversum - which are all private companies.

SCHUFA is especially bad. They gather some strange data, and then "based on statistical analysis" give you a rating that is completely disconnected from reality. It's borderline necessary to rent an apartment, but if you're a new expat, have 2 credit cards, NOT (!) paying a mortgage, or you like to move apartments often, or try buying something with installments and get rejected (...via SCHUFA check...), then you're in a shitlist without any recourse.

Re: You Know GDPR Is Good Based on Who Hates It

#135
post #30

Earlier quoted context omitted.

I'm responsible for GDPR in a small European company that processes fairly sensitive data. It's not that complicated as people like you make it out to be - if you're willing to actually try to do the right thing.

[flagged]

> GDPR is easy to implement once, but it is constantly changing every year.

No it’s not. If you’re running an online store, compliance is pretty straightforward. Most of the PII you collect has a good reason: payment, fulfilment, fraud prevention, etc. so you don’t need consent for that.

If you’re collecting marketing data, you need to ensure it’s clear that you’re using it for that and keep your records accurate if you’re informed they changed.

For store analytics, your cookie banner covers you, the major players all integrate into standard tools, and they keep their compliance up to date, so you’re fine there.

Small mistakes are very much not punished. Your country’s Data Commissioner equivalent will want to see you try to be compliant first. You’re only going to get put out of business on a first offence if you’re taking the piss. I guarantee any example you provide me as evidence will be exactly that, but feel free to try.

Re: You Know GDPR Is Good Based on Who Hates It

#136
post #33

Banner gets a lot of attention because of the never-ending annoyance it's causing. It's like being surprised that someone would care about something so small as a little rock in their shoe. Yeah, you care about these little things. It is also definitely true that the regulations are largely written by people who do not understand the tech they're regulating and its potential. Again, not some weird controversial point…

The purpose of GDPR was never data protection or privacy. It was designed to legitimise data trade and give corporations legal basis for selling and processing the data where before that it was a grey area. If you look at it through that lens, it will make sense. Regulators are just a potemkin village thing to make it look like the law is serving ordinary person.

You're lying.

Re: You Know GDPR Is Good Based on Who Hates It

#137

Earlier quoted context omitted.

[flagged]

> GDPR is easy to implement once, but it is constantly changing every year. No it’s not. If you’re running an online store, compliance is pretty straightforward. Most of the PII you collect has a good reason: payment, fulfilment, fraud prevention, etc. so you don’t need consent for that. If you’re collecting marketing data, you need to ensure it’s clear that you’re using it for that and keep your records accurate if…

> the major players all integrate into standard tools, and they keep their compliance up to date,

I am not major player! I do not have dedicated team of people to keep "compliance up to date".

> if you’re informed they changed

Yet more extra work!

> see you try to be compliant first

Sounds like work for extra GDPR officer! I do not have that kind of money!

Re: You Know GDPR Is Good Based on Who Hates It

#138
post #130

Earlier quoted context omitted.

> Which one is it then? You don’t need a dedicated data protection officer, because your company is too small for that. You also don’t have to abide by lots of regulations that only apply to bigger businesses. But you still need to comply with the basic requirements, and that is your job as a business owner. I know what I am talking about, because this is part of my job. So unpaid doesn’t really match the reality her…

> You don’t need a dedicated data protection officer, because your company is too small for that. But I do need dedicated comliance officer! The lower thresholds applies from 250 employees. I still have the same obligations as larger companies! And if do notmp comoly goverment will fine me to oblivion! > So unpaid doesn’t really match the reality here, right? It absolutely matches the reality. You expect me to do stu…

> But I do need dedicated comliance officer!

There is no compliance officer required by law, at least not in any regulation introduced by the EU.

> The lower thresholds applies from 250 employees. I still have the same obligations as larger companies!

If you have more than 250 employees, you really should have both a higher salary than a garbage man and be able to afford someone to take care of your compliance duties.

> You expect me to do stuff for free. Or can I demand extra money to match minimal salary on my tax return?

I don't expect anything. You run a business. Anything you do related to that business is your own working time, just as anything I do in regard to compliance or data protection is of course billed working time. You file your taxes in your working time, you pay your bills in your working time, and of course you also read up on laws you need to comply to in your working time. Those are table stakes for doing business everywhere. Do you think American companies don't have to comply to regulations?

> Because I have social responsibility to make some rare stuff available, as you would put it!

All props to you for making that choice, then, but it's still your decision to have a company and that means you have to abide the law.

> But EU is not making it any easier!

The EU is responsible for so many things you just take for granted: A single market larger than the USA with a single currency; hundreds of EU-funded programs for small businesses with grants available easily; common standards across the entire union; protection from foreign traders; cross-border regulation and mobility; even things like funding for public infrastructure, art, and education all around you that you don't know of, because you never cared to look.

Just because you have a responsibility to think about and extra work to enable handling data your customers entrust you with carefully doesn't invalidate all of these efforts.

> So at end I should hope for the best right and relly on merci? My gov just loves to skull fuck "capitalists"!

You should try to think about protecting the personal data you handle responsibly and be ready to demonstrate that when somebody asks. Again, I am in the same spot and have been for years. This is doable.

Re: You Know GDPR Is Good Based on Who Hates It

#139

Earlier quoted context omitted.

If you're in a shopping site and "add to basket" -- explicity requested. If each page you browse on the shopping site shows what's currently in your basket -- explicitly requested. If you checkout and get a list of what's in the basket and give you card details for payment and email for receipt -- explicitly requested. No consent needed. On the other hand, deliberately analysing log data after the fact for which prod…

Dropping permanent cookies for any of this stuff is not strictly necessary; session cookies would be sufficient, so then to do anything convenient (e.g. persistent cart, Amazon-style) but not necessary you still need to request consent. GDPR's legitimate interest basis is better written. But ePD is not superceded by GDPR, they are layered on top of each other.

That sounds like a wheeze that I've heard before.

Site builders argue to themselves that what the regular user would want to do -- e.g. close the site and browser, come back to it and expect the items in the cart are remembered (for some amount of time, e.g. a month, not forever) -- is something the GDPR (or ePR) would strictly prohibit. Neither prohibit this. You can use persistent cookies or local storage for maintaining the user's cart.

The reason they massively overstate what the regulations prohibit is because there are many things they want to do: user tracking and analytics, marketing engagement, etc., and know fine well the regulations prohibit that unless they get consent. So they pretend they can't possibly even do a basically functional site without getting consent, which is bollocks, so they don't feel so bad about imposing a consent banner on every visitor.

The same thing happened in the UK where businesses told customers lies that "Health & Safety made me do this" or "the EU made me do this"

https://web.archive.org/web/20190627174442/http://www.hse.go...

https://web.archive.org/web/20200131200512/https://blogs.ec....

Re: You Know GDPR Is Good Based on Who Hates It

#140

Earlier quoted context omitted.

> GDPR is easy to implement once, but it is constantly changing every year. No it’s not. If you’re running an online store, compliance is pretty straightforward. Most of the PII you collect has a good reason: payment, fulfilment, fraud prevention, etc. so you don’t need consent for that. If you’re collecting marketing data, you need to ensure it’s clear that you’re using it for that and keep your records accurate if…

> the major players all integrate into standard tools, and they keep their compliance up to date, I am not major player! I do not have dedicated team of people to keep "compliance up to date". > if you’re informed they changed Yet more extra work! > see you try to be compliant first Sounds like work for extra GDPR officer! I do not have that kind of money!

By “major player” I meant the analytics companies that you pay, not you.

> Yet more extra work!

If “customer asks me to update my records on them, so I do it,” is too much work then you really shouldn’t be in the business that requires it.

> Sounds like work for extra GDPR officer!

Or you just ask “what do I need to do?” The official tells you, you do it, they say “thank you.”

Seriously, all your answers here tell me you’re trying to do some shady shit and not even making money from it. If you were a simple retailer, as your original post implied, you would not be worried about the complexity of handling GDPR.

Post reply on HN