Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

121–130 of 833 posts

Re: GDPR: Don't Panic

#121

Earlier quoted context omitted.

Stop spamming every single comment on this thread. Your question is irrelevant and misdirected - I've literally started my argument by saying that "there's currently no case law surrounding GDPR".

Your argument is that there is no case law so you get to claim whatever imaginary consequence you want. That’s fine but then other people may debate your conclusions. You’re also claiming people are rightfully concerned. Where is that right coming from? From past experience? Or is they just baseless concerns?

> "Your argument is that there is no case law so you get to claim whatever imaginary consequence you want."

No, that's not my argument at-all. That's just your personal interpretation of my words.

> "You’re also claiming people are rightfully concerned."

I'm not "also claiming". That was the sole claim from the very start.

> "Where is that right coming from? From past experience? Or is they just baseless concerns?"

It's literally in the comment:

(1) Some elements of the GDPR are up for interpretation.

(2) There's currently no case law surrounding GDPR.

If you take both of these facts into account - it is perfectly plausible for people to be concerned, as there's no telling how things will play out in a court of law.

Re: GDPR: Don't Panic

#122
post #79

For those of you understandably intimidated by the GDPR regulations themselves, here's a good summary in plain English: https://blog.varonis.com/gdpr-requirements-list-in-plain-eng... The UK's ICO also has a good structured summary: https://ico.org.uk/for-organisations/guide-to-the-general-da... In general I agree with the sentiments in this article. I've probably spent a total of three to four days reading around th…

That Varonis link gets posted quite a bit, but it drastically over simplifies things and even tries to poke fun at some aspects of the legislation. The ICO site is a much better read for this.

Fair point - my intent was to point out that some sources which are less intimidating than others. If all you read was the Varonis link you'd be in trouble, but if someone's the kind of person who thinks that they can read one blog post and understand the GDPR I'm not sure they're the kind of person that can be helped anyway...

Re: GDPR: Don't Panic

#123
post #80

Earlier quoted context omitted.

The regulators have been running for two decades, and this is EXACTLY how they operate. Scepticism in this case is unreasonable, given the massive evidence base.

But that's purely your own opinion. I do have some direct experience of working with EU data protection regulators. My experience has been that they vary wildly in "reasonableness". UK ICO is pretty OK, they want companies to succeed. France's CNIL is a joke. Petty, spiteful and utterly inconsistent. I watched as a company worked closely with them to get their sign-off on a change to their terms of service and privac…

_But that's purely your own opinion_

It’s also the opinion of every regulatory lawyer!

I don’t really see what the alternative is. It’s painfully obvious that a regulation like this is needed. Like any regulation, there will be a period of bedding in while we work out the actual bounds and procedures required.

I’m curious then what your alternative proposal for implementing this regulation would be, assuming you think it’s something that needs to be regulated at all.

Re: GDPR: Don't Panic

#124
post #48

This doesn't consider some factors that dictate how strong any company will experience their firehose of GDPR requests to be: - how incentivised people are to make GDPR subject access requests of the company (how angry, confused, hostile curious they are) - how easy it is for them to make requests (entirely manual vs. online service) - wildcard factors (internet flash mobs bent on vengeance against a corporate) There…

You can do this already with the existing Data Protection Act. Businesses have not drowned in subject access requests. People seem to forget that data protection isn't new, it's just being beefed up a bit.

https://ico.org.uk/for-organisations/guide-to-data-protectio...

Another link from 2012 describing how to handle data protection in the 1998 framework: http://www.shoosmiths.co.uk/client-resources/legal-updates/D...

Re: GDPR: Don't Panic

#125
post #80

Earlier quoted context omitted.

But that's purely your own opinion. I do have some direct experience of working with EU data protection regulators. My experience has been that they vary wildly in "reasonableness". UK ICO is pretty OK, they want companies to succeed. France's CNIL is a joke. Petty, spiteful and utterly inconsistent. I watched as a company worked closely with them to get their sign-off on a change to their terms of service and privac…

Furthermore, it imposes unbelievable costs on companies that in the end must be passed on to consumers. This is completely unnecessary legislation that will probably have no measurable positive effect at all. Bureaucracy and politics at its best.

Why is this unnecessary? We see daily announcements about personal data being leaked and misused. It’s plainly a problem.

Re: GDPR: Don't Panic

#126
post #71

Earlier quoted context omitted.

How do you check if someone is an EU resident?

Geolocation, IP Lookup etc. You generally shouldn't care whether they're a resident in the EU, but just whether they are in EU or not. Remember GDPR doesn't cover any citizens from EU who aren't in EU.

I read that GDPR applies to EU residents. That means someone who is EU resident non necessarily could be browsing from the EU. For example when on holidays.

Re: GDPR: Don't Panic

#127

Earlier quoted context omitted.

How do you check if someone is an EU resident?

same with the age check, you ask them

Not sure why you got down voted as it is correct.

When you do business with a customer asking for the location is a common part of the sign up process.

We're talking about a law that is about data gathering, if you're not gathering data about that customer there's nothing to worry about.

Re: GDPR: Don't Panic

#128

Earlier quoted context omitted.

Am in EU, am involved in some compliance stuff and have talked to plenty others at other companies, and it really does seem to be a nothing-to-see-here for all companies except the sleezy ones.

In all of my research, talking to lawyers, and seminars on GDPR, it is about: 1. Ask permission for collecting data 2. Keep sensitive data safe 3. Restrict access to said data 4. Keep a log of what happens with the data 5. Delete it upon request 6. Have all of the above documented and adhere to the protocol. It's such a none issue unless you're relying on the very thing GDPR is designed to combat. If you not collecti…

Yes.

And even (1) isn't always needed. There are several justifications for processing personal data, and permission is only one of them. (Although for compliance it is the easiest)

https://gdpr-info.eu/art-6-gdpr/

And (5) has a bunch of caveats. You don't always need to delete data.

Right to Erasure: https://gdpr-info.eu/art-17-gdpr/

Re: GDPR: Don't Panic

#129

Earlier quoted context omitted.

The amount of discretion and lack of clarity in the penalties is part of the problem. It opens you up to risk based on the whims of politics and the regulators and increases uncertainty. Laws should be clear, limited, and understandable - this is not.

In an ideal world, yes. But that leads you down a Kafkaesque hole of bureaucracy - at some point you have to stop adding detail and leave things open to interpretation. There are plenty of laws out there with fines "up to €X" and, from my limited experience, I don't think the GDPR is especially ambiguous compared to others.

Well, lots of ends open to interpretation, and $20 mln fine - so obviously nothing to care about! Hysteria!

Re: GDPR: Don't Panic

#130
post #80

Earlier quoted context omitted.

The regulators have been running for two decades, and this is EXACTLY how they operate. Scepticism in this case is unreasonable, given the massive evidence base.

But that's purely your own opinion. I do have some direct experience of working with EU data protection regulators. My experience has been that they vary wildly in "reasonableness". UK ICO is pretty OK, they want companies to succeed. France's CNIL is a joke. Petty, spiteful and utterly inconsistent. I watched as a company worked closely with them to get their sign-off on a change to their terms of service and privac…

> CNIL then immediately changed their mind and dished out a fine

So, there's no opportunity for litigating using their previous statements? At least now I understand why you're on every GDPR thread.

Post reply on HN