Live data from Hacker News

GDPR and Google Analytics

adactio.com

101–110 of 130 posts

Re: GDPR and Google Analytics

#101

Earlier quoted context omitted.

And sure, by German law, your data will be deleted after you paid your fine. (Plus some time for processing and record keeping) This doesn’t make this a good analogy though. The GDPR does not prohibit storing private data, it just requires explicit and informed consent. It does not require deletion of data that is required to conduct a transaction, such a receipts, order data or adresses required to fulfil an order.…

The GDPR isn't as good as you think it is. It's going to turn into one of those laws where small software startups / or normal small businesses are just going to be in constant violation, because the amount of resources required to do it properly requires a team of 5 or 10 expensive software engineers. It's going to be a great way to nip small companies in the bud and consolidate this kind of stuff into bigger compan…

> Read this to see more from the small company side and how much of a mess it is:

> https://www.brentozar.com/archive/2017/12/gdpr-stopped-selli...

I read his post, and wonder if the 'attorneys' he consulted are specialists in EU law, or were his standard ones. There's a lot of FUD around GDPR but the guidance is getting better, and people assume it's being 'policed' when the UK's body (the ICO) is more about guiding into best practices than punishment.

The comments (esp around medical records) suggest ignorance of how it's working.

Source: reading the GDPR and accompanying notes from the ICO; discussions with a large company's GDPR advisor, who was involved in drafting the legislation.

Disclaimer: this is not legal advice, I am not a lawyer, and you are an idiot if you act on anything I say.

Re: GDPR and Google Analytics

#102
Let’s all have a moment of silence for John Perry Barlow’s Declaration of Cyberspace Independence back when it was envisioned the internet would be a place where any entities could communicate or associate free of government control or censorship.

Loads of people in here who support the concept of net neutrality which helps enable permissionless innovation by not imposing huge costs on those who publish or allowing others to impose costs on them, now cheerlead for the right to impose extraterritorial regulation without representation.

There was a time you could just set up a site on the net and not have to worry about much, apparently now you have to worry about the Union of all possible foreign laws in case anyone from outside geographic regions visits your site. It’s could be a race to the lowest common denominator of freedom, or conversely yield bulkanizarion of the internet as more Geo-IP blocks go up or more great firewalls.

How many of you love “this video or music isn’t available for playback in your region”?

That could be much more common in the future and contrary to commentary far more likely to hurt smaller and medium sized players than the real targets of the laws.

Re: GDPR and Google Analytics

#103
post #84

Earlier quoted context omitted.

Data retention policies in GDPR specifically address the case, if there is a legal reason to keep the data it should take precedence. That's it you can't tell that you wish your 10k euro bank credit to be forgotten. Accounting logs might need to be kept up to seven (in some cases 10) years, so the data related to them should be kept. The data is sort of field based and some might need to be able to be forgotten earli…

So if another country says it's not legal to comply with the GDPR in their country, they get off scot free? :P

totally, but then again you won't be able to transact with the EU, besides all the diplomatic aftermath.

Re: GDPR and Google Analytics

#104

Let’s all have a moment of silence for John Perry Barlow’s Declaration of Cyberspace Independence back when it was envisioned the internet would be a place where any entities could communicate or associate free of government control or censorship. Loads of people in here who support the concept of net neutrality which helps enable permissionless innovation by not imposing huge costs on those who publish or allowing o…

You can still set up a site and not have to worry about much, as long as you're not processing other peoples personally identifiable information without their explicit consent.

Re: GDPR and Google Analytics

#105

Earlier quoted context omitted.

> It seems strange to me to have this enforcement of policies from countries that are not my own just because my website is accessible from those countries. If you open shop in a different country, you follow their laws. Your website being accessible in a country is seen as the same thing. It's not hard to implement geo blocking if you want to show best effort and thereby opt out of it.

This can very quickly become onerous for anyone wanting to run a website, if they have to understand the law of any country where it might be accessed. I think the onus of geoblocking should be in the country that decides this website doesn't obey it's laws, otherwise only large corporations with lawyers will be able to run websites. If your website is doing business (i.e. Has some sort of legal presence) in another…

If I'm just serving cat pictures, then I agree. But as soon as money and/or PII is involved, then a different set of rules apply.

Re: GDPR and Google Analytics

#106
post #92

Earlier quoted context omitted.

If you want to do business with EU citizens, you have to follow EU law. Before the internet, you had to open a shop here, or send your goods over the border. The only thing that has changed is the fact that you provide a virtual service over the internet.

No, if I want to have a physical presence in the EU I have to follow EU law. But if I'm residing entirely in another country, and EU citizens want to do business with me over the internet, I could care less what EU law says. And no amount of whining on this thread will change the fact that the EU has no leverage over me.

So, you do not care one iota about laws, or security of PII and other sensitive information, unless there can be sanctions against you?

Regardless, businesses have been dropped from their payment provider for less, so there is certainly leverage.

Re: GDPR and Google Analytics

#107
post #92

Earlier quoted context omitted.

If you want to do business with EU citizens, you have to follow EU law. Before the internet, you had to open a shop here, or send your goods over the border. The only thing that has changed is the fact that you provide a virtual service over the internet.

No, if I want to have a physical presence in the EU I have to follow EU law. But if I'm residing entirely in another country, and EU citizens want to do business with me over the internet, I could care less what EU law says. And no amount of whining on this thread will change the fact that the EU has no leverage over me.

If I break US law over the internet against a US company/person, even though I do no business in the US, have never been there, and don't plan to be there, guess how long before I'm dragged making license plates with words like "liberty" or "freedom" on them in an American rape gulag?

Re: GDPR and Google Analytics

#108
post #13

Earlier quoted context omitted.

Why are you storing and processing their data if not for profit?

personal data in the GDPR has a very expansive definition, and definitely includes things like IP. Processing likewise has an expansive definition, including collection and recording. Lots of sites will be processing and storing this data for internal analytics.

So just don't do internal analytics. Or, if you feel you must, ask consent first. Easy peasy.

Re: GDPR and Google Analytics

#109
post #60
post #11

Earlier quoted context omitted.

Probably... not really? Maybe? For starters, if you don't take payment and aren't in the EU, EU enforcement power is going to be extraordinarily limited. And even if you do require payment, if you don't have a physical nexus in the EU, it's unclear what exactly the EU can do? I think the GDPR was basically aimed at some of the scummier adtech practices and businesses like Facebook, and for those, it will be very enfo…

> And even if you do require payment, if you don't have a physical nexus in the EU, it's unclear what exactly the EU can do? You need an EU VAT ID to accepts payments from EU citizens. So they will revoke that and then you can't accept payments from EU.

> You need an EU VAT ID to accepts payments from EU citizens.

This was mentioned before: No, you don’t.

Millions of business around the world accept transactions from EU citizens every day without collecting any VAT or having any relationship with the EU.

Re: GDPR and Google Analytics

#110
post #104

Let’s all have a moment of silence for John Perry Barlow’s Declaration of Cyberspace Independence back when it was envisioned the internet would be a place where any entities could communicate or associate free of government control or censorship. Loads of people in here who support the concept of net neutrality which helps enable permissionless innovation by not imposing huge costs on those who publish or allowing o…

You can still set up a site and not have to worry about much, as long as you're not processing other peoples personally identifiable information without their explicit consent.

But then you don't consider the IP address personally identifiable information? The GDPR does.
Post reply on HN