Live data from Hacker News

GDPR – A Practical Guide for Developers (2017)

techblog.bozho.net

111–120 of 202 posts

Re: GDPR – A Practical Guide for Developers (2017)

#111
post #78

As a freelance developer I'm quite sure that if I were to force my clients to comply with as strict an interpretation of GDPR as this, I would pretty shortly find myself replaced by a freelance developer with a more relaxed attitude to GDPR compliance.

This is probably true. If I were in this situation, I would probably only make suggestions and not force compliance.

Re: GDPR – A Practical Guide for Developers (2017)

#112
It seems likely this will lead to increased centralization and/or standardization as many website owners decide it is too complicated and risky to write custom software managing their own user accounts.

This might be similar to how merchants often sell through larger websites like Amazon, or mobile developers sell through app stores.

Or, much like many startups begin with Bootstrap for their CSS and Django provides a built-in admin user interface, perhaps there will be open source skeleton web apps that have all the data models and UI needed for GDPR?

It sounds like there will be lots of business opportunities here.

Re: GDPR – A Practical Guide for Developers (2017)

#113
post #85
post #83

Earlier quoted context omitted.

This is the biggest problem with GDPR, there's no agreement what it means, but it will go into effect in a few weeks.

What is “it”? GDPR is in large parts based on the Data Protection Directive from 1995 and “Convention 108” from 1981. There is ample of case law, data protection authority opinions, guidance, etc.

GDPR will go into effect this month.

EDIT: My mistake, in May

Re: GDPR – A Practical Guide for Developers (2017)

#114

Earlier quoted context omitted.

What personal information does bitcoin contain?

All payment orders and credit transfers to and from all accounts. For any Bitcoin address you find on the Web.

Is Bitcoin identifiable? Or is an association to a Bitcoin transaction in a payment system identifiable? Which would mean the personal info could be removed in the payment system

Re: GDPR – A Practical Guide for Developers (2017)

#115
What happens if your service lets users manage their own customers’ data? I mean, for a product such as Airtables, FieldBookApp, Sharepoint Forms or, simply, Google Forms: Are we, cloud app providers, supposed to ensure our users don’t put PII data in the spreadsheets, and if they do, are we supposed to manage their users’ consent and process their users’ requests for edition and deletion? At the extreme, what should Heroku do for the Postgres darabases they provide to their customers ?

I could only find GDPR blogs about apps facing the final users, but they generally don’t talk about compliance for B2B apps.

Re: GDPR – A Practical Guide for Developers (2017)

#116
post #93
post #84

Earlier quoted context omitted.

There's plenty of alternatives. The main problem with GDPR is not the goal of advocating privacy but the details. I would have done it like this: a) bring out regulation gradually instead of in a single big change like GDPR to have companies time to comply b) don't write vague laws c) give specific examples of what GDPR means in practice d) be more lenient on smaller companies

a) companies had 2 years go comply. Furthermore, the guidlines of the European Commission are clear that the process should be gradual - inspect, write recommendations, small fines, bigger fines. Nothing like "20 million in June" b) the law had to cover a lot of usecases and in order to do that concisely, it may sound vague in places. I also don't like (developers never like uncertainty), but there's established prac…

a) The problem with this is that this practical guide was released in November 29, 2017. And this is unofficial. EU should have released a practical guide two years ago in my opinion.

If the process is gradual the law should reflect that.

c) Good to hear :). Apparently it's this: https://ico.org.uk/for-organisations/guide-to-the-general-da... - I hope it's not written from the perspective of the UK legislation.

d) The law should clearly define what is required for smaller companies and what is not. There's some disagreement if this is the case in GDPR articles too.

Re: GDPR – A Practical Guide for Developers (2017)

#117
post #96
post #84

Earlier quoted context omitted.

There's plenty of alternatives. The main problem with GDPR is not the goal of advocating privacy but the details. I would have done it like this: a) bring out regulation gradually instead of in a single big change like GDPR to have companies time to comply b) don't write vague laws c) give specific examples of what GDPR means in practice d) be more lenient on smaller companies

> a) bring out regulation gradually instead of in a single big change like GDPR to have companies time to comply GDPR wasn't announced yesterday. The time span between announcement and implementation date is over two years . Of course if you only start now there isn't much time left, but then that's your own fault.

GDPR was announced years ago, but this pratical guide was authored a few months ago. EU should have released an official guide two years ago.

Re: GDPR – A Practical Guide for Developers (2017)

#118
post #74

Earlier quoted context omitted.

One man shop here... Cloudfront forwards country information to your origin servers in AWS. My plan was to not do business or display content in European countries until an easy solution to GDPR enables me to quickly meet it's criteria. Certainly libraries will crop up helping to ease the burden of the regulation for smaller operations. Though... I'm not quite sure what happens when a European citizen uses VPN to spo…

I cannot imagine why anyone would want to intentionally violate someone's privacy and ignore their stated preferences; to use their data in a way they would not want, regardless of what country they live in. It surprises me that anyone would want to make an insecure system on purpose and take no responsibility for being hacked. That's what "ignoring the GDPR" means on some level. It just so happens that the GDPR prov…

Fair enough. Here's what I'll promise you: I'll dig more into GDPR for my side projects, and will opt to shut down projects (instead of fire walling them) if it the effort to conform to GDPR is too large, while I bring my projects up to standard.

Re: GDPR – A Practical Guide for Developers (2017)

#119
post #84

Earlier quoted context omitted.

There's plenty of alternatives. The main problem with GDPR is not the goal of advocating privacy but the details. I would have done it like this: a) bring out regulation gradually instead of in a single big change like GDPR to have companies time to comply b) don't write vague laws c) give specific examples of what GDPR means in practice d) be more lenient on smaller companies

a) It is not a big change from the 1995 regulation. It is incremental. There is a feeling that the previous regulation lacked teeth with the multinationals, some of whom have chosen to ignore it. Facebook have lost two cases over aggregating data in Belgium and Germany in the last month. b) I don't know if you are familiar with European law, but what you see as vague is what others see as flexibility. Laws setting ou…

Well, I personally don't like laws to be vague.

Re: GDPR – A Practical Guide for Developers (2017)

#120
post #85

Earlier quoted context omitted.

What is “it”? GDPR is in large parts based on the Data Protection Directive from 1995 and “Convention 108” from 1981. There is ample of case law, data protection authority opinions, guidance, etc.

GDPR will go into effect this month. EDIT: My mistake, in May

It will apply from 25 May 2018
Post reply on HN