Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

111–120 of 833 posts

Re: GDPR: Don't Panic

#111
post #79

Earlier quoted context omitted.

That Varonis link gets posted quite a bit, but it drastically over simplifies things and even tries to poke fun at some aspects of the legislation. The ICO site is a much better read for this.

Pardon me but, what does ICO site mean in this context?

Information Commissioner's Office: https://ico.org.uk/about-the-ico/

Re: GDPR: Don't Panic

#113
post #37

The problem of multiple ambiguities in GDPR hasn't really been addressed here. Also, must be nice to live in a country where the regulator is as benevolent and reasonable as is described in this article. I think it's ok for foreigners to be skeptical of this promise, as the article implies that this reasonableness is not encoded in law.

> that this reasonableness is not encoded in law.

This is the main issue with this regulation in my opinion. Some of the recent statements by EU officials on that matter verge on absolutist notions of law: "Don't worry. Authorities will be lenient and benevolent." This is how absolutist kings argued why there shouldn't be a constitution or a state under the rule of law.

Re: GDPR: Don't Panic

#114
post #60

Earlier quoted context omitted.

I think this is a very distinct difference between the EU with the scaremongering removed, and e.g. the US: My experience of the EU has been that they've consistently looked out for my interests. Even in the face of the local government (I live in the UK) that have kept fighting for positions I find abhorrent (e.g. UK governments keep complaining about having to abide by EU human rights regulations for example). Yes,…

You are transposing your like of certain EU institutions (human rights regulations) and grafting them onto this legislation. This isn't how it works, not least because there has been no case-law yet, so we have no idea how it will be interpreted. Therefore a legal compliance unit has no choice but to follow GDPR the letter, which is hugely difficult and bureaucratic. The notion that they are "good-natured" is meaning…

As mentioned elsewhere, these regulators have been operating for a very long time. Even when dealing with the whole Facebook / Cambridge Analytica they're moving quite slowly. There have been various legal changes regarding privacy in the past. E.g. for The Netherlands it is not allowed to have a checkbox on by default to sign up to a mailing list. There's a fine if you don't abide and this fine can be very hefty. In case of problems the regulator first reaches out, a fine is the very last resort.

There has been ample history on how these regulators have been working over the past 20-40 years.

Re: GDPR: Don't Panic

#115

Earlier quoted context omitted.

on what experience about gdpr case law is the linked article basing his statement? all those claims about warning shots and leniency and goodwill of the regulator are completely unfounded. the linked article makes the claim, the linked article should substantiate the claims, and we maintain a healthy right to remain skeptical of those claims until some meat is added to them.

The DPA (Datatilsynet) in Denmark operates in the exact way stated in the article. I've fairly sure it's the same in Sweden, Germany, UK, and most of the EU. It is in stark contrast to the US. I'm not going to link cases, because they're in Danish. They are available from their webpage, and the most resent ones are linked on the frontpage. The last few cases large companies was not in compliance and the didn't get a…

That's supernice for you in supernice Denmark. Now what about all the other EU countries? What about in 5 years time if things become less supernice. 10 years time?

Re: GDPR: Don't Panic

#116
post #47

Earlier quoted context omitted.

Do you have any experience with a Eu country internet regulatory service? I have experience with the CNIL (The french one), and they were helpfull and yes, good-natured. Part of our demand to be able to host data from hospital was drafted with their help, when they had no legal obligation to help us. A friend who work in a legal/tech startup also had good experience with them, and i don't know anybody who ever had a…

You seem to have misunderstood my comment. I was saying that from a legal complience perspective, the notion that the regulatary body is "good-natured" is meaningless. You have to comply with ever letter of the GDPR, you can't just do most of it, or interpret it loosely, and say "oh but they are good-natured people they will understand.". Legal complience doesn't work like that AT ALL!

> I was saying that from a legal complience perspective, the notion that the regulatary body is "good-natured" is meaningless.

It's not, because as the article explains, experience with the existing regime shows that, the good natured regulator will send you a helpful and explanatory warning letter that tells you what you need to do to become compliant before jumping into fines.

An un-good-natured regulator would behave rather differently.

Re: GDPR: Don't Panic

#117
post #80

Earlier quoted context omitted.

But that's purely your own opinion. I do have some direct experience of working with EU data protection regulators. My experience has been that they vary wildly in "reasonableness". UK ICO is pretty OK, they want companies to succeed. France's CNIL is a joke. Petty, spiteful and utterly inconsistent. I watched as a company worked closely with them to get their sign-off on a change to their terms of service and privac…

"his belief that everyone working in GDPR enforcement in the EU will not only be totally predictable and reasonable today but also going forward into the indefinite future." EXACTLY! There seems to be an almost cultish devotion to the benevolent institution that it can do no wrong, neither now nor henceforth. I understand WHY people have this belief. The EU is under constant attack at the moment from many sides, and…

But people aren't defending Europe, they're defending the national data protection regulators (eg ICO) which are not European bodies.

Re: GDPR: Don't Panic

#118
post #47

Earlier quoted context omitted.

Do you have any experience with a Eu country internet regulatory service? I have experience with the CNIL (The french one), and they were helpfull and yes, good-natured. Part of our demand to be able to host data from hospital was drafted with their help, when they had no legal obligation to help us. A friend who work in a legal/tech startup also had good experience with them, and i don't know anybody who ever had a…

You seem to have misunderstood my comment. I was saying that from a legal complience perspective, the notion that the regulatary body is "good-natured" is meaningless. You have to comply with ever letter of the GDPR, you can't just do most of it, or interpret it loosely, and say "oh but they are good-natured people they will understand.". Legal complience doesn't work like that AT ALL!

What people mean when they say the agency is "good-natured" is not that they're going to ignore non-compliance, but that the way they enforce it is not being completely hostile and pulling out a massive lawsuit the second they see any issues.

Their goal is not to destroy companies, it's to make them compliant, and it's much easier for them to do that with communication than expensive legal action.

Re: GDPR: Don't Panic

#119

For those of you understandably intimidated by the GDPR regulations themselves, here's a good summary in plain English: https://blog.varonis.com/gdpr-requirements-list-in-plain-eng... The UK's ICO also has a good structured summary: https://ico.org.uk/for-organisations/guide-to-the-general-da... In general I agree with the sentiments in this article. I've probably spent a total of three to four days reading around th…

The amount of discretion and lack of clarity in the penalties is part of the problem. It opens you up to risk based on the whims of politics and the regulators and increases uncertainty. Laws should be clear, limited, and understandable - this is not.

In an ideal world, yes. But that leads you down a Kafkaesque hole of bureaucracy - at some point you have to stop adding detail and leave things open to interpretation. There are plenty of laws out there with fines "up to €X" and, from my limited experience, I don't think the GDPR is especially ambiguous compared to others.

Re: GDPR: Don't Panic

#120
post #48

This doesn't consider some factors that dictate how strong any company will experience their firehose of GDPR requests to be: - how incentivised people are to make GDPR subject access requests of the company (how angry, confused, hostile curious they are) - how easy it is for them to make requests (entirely manual vs. online service) - wildcard factors (internet flash mobs bent on vengeance against a corporate) There…

I agree, and there seems to be a lack of conversation around this! Next week could be ground-zero for all sorts of unintended consequences. Especially, a flashmob of GDPR requests could sink a company.

It is highly unlikely that a lot of requests will "sink" your company. As per the GDPR, you have a month to respond to requests and you can extend this period by two more months by telling the user that you need more time to process their request. (See article 12 for reference)
Post reply on HN