Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

151–160 of 833 posts

Re: GDPR: Don't Panic

#151
What really annoys me about GDPR is that, given all the confusion surrounding the law, a lot of GDPR professionals are popping up everywhere.

There are a lot of people making money by providing GDPR-compliant-solutions. To avoid this, all that had to be done was to write a clear text with everything everyone had to do to be compliant, instead of pilling up some big and dubious words that no one really knows what they mean.

Concerning the law itself, it's a lot of fireworks. Give it a few months and no one will care about it again.

Re: GDPR: Don't Panic

#152
post #47

Earlier quoted context omitted.

Do you have any experience with a Eu country internet regulatory service? I have experience with the CNIL (The french one), and they were helpfull and yes, good-natured. Part of our demand to be able to host data from hospital was drafted with their help, when they had no legal obligation to help us. A friend who work in a legal/tech startup also had good experience with them, and i don't know anybody who ever had a…

You seem to have misunderstood my comment. I was saying that from a legal complience perspective, the notion that the regulatary body is "good-natured" is meaningless. You have to comply with ever letter of the GDPR, you can't just do most of it, or interpret it loosely, and say "oh but they are good-natured people they will understand.". Legal complience doesn't work like that AT ALL!

They will understand and give you a warning before doing anything and let you change your malpractice before any reaction. That's how it works.

Re: GDPR: Don't Panic

#153

For those of you understandably intimidated by the GDPR regulations themselves, here's a good summary in plain English: https://blog.varonis.com/gdpr-requirements-list-in-plain-eng... The UK's ICO also has a good structured summary: https://ico.org.uk/for-organisations/guide-to-the-general-da... In general I agree with the sentiments in this article. I've probably spent a total of three to four days reading around th…

The amount of discretion and lack of clarity in the penalties is part of the problem. It opens you up to risk based on the whims of politics and the regulators and increases uncertainty. Laws should be clear, limited, and understandable - this is not.

The law says that the fines should be "effective, proportionate and dissuasive". That gives companies ample room to challenge a fine that is way out of proportion to the damages caused to their users.

Re: GDPR: Don't Panic

#154
post #64

Earlier quoted context omitted.

Not an alternative - but the only obvious defence is to do the right thing, and delete data as soon as you have completed processing. e.g. delete those interview notes the second you have declined the candidate.

That's ridiculous. Has anyone in this thread actually ever run a recruiting operation? I have. There's no way we will be deleting interview notes the moment a candidate is rejected. For one, we have to be able to prove later that we didn't reject based on grounds of discrimination (other regulations). But you also need the ability to review what your interviewers are doing to ensure consistency and quality of assessm…

> I have argued above that I legitimately need interview notes for the operation of my business.

I agree that you do legitimately need interview notes, but I don't understand why this conflicts with GDPR. In other words, why am I not allowed to see my interview notes?

Re: GDPR: Don't Panic

#156
Dont panic. Panic when you get something like this.

https://www.linkedin.com/pulse/nightmare-letter-subject-acce...

Bottom line, DONT store/sell/mangle with personal data of your users unless you are able to fulfill this. I was thinking a bit about having an online store:

- make login as it is on Hacker News, you dont need email

- once user has selected and payed the goods, request sending address and contact (phone/email/whatever)

- ship it, print the requested / store into cold store (it is not that hard, you do it for bitcoins, right?), delete everything except username and password (and maybe the attached goods) from server

The described process will pass the GDPR Nightmare Letter in 10 minutes (to write a general reply) that you sent to everyone requesting.

This is what traditional "physical" stores do, not the large chains, the traditional, one employee, family store. And it works.

For everything else require consent, including tracking, but think very hard if you need anything else as it will complicate your business progressively.

I really dont understand all the fuss about the GDPR, if you explain (and prove) this to ICO, I would really like to see who will punish you for that.

Re: GDPR: Don't Panic

#157

Earlier quoted context omitted.

What you're describing is the way common law works. Most European jurisdictions work under a civil law system.

It's not black and white, precedent exists in civil law systems as well: https://en.wikipedia.org/wiki/Precedent#Civil_law_systems

Yes, common law and civil law systems have been converging to some extent. In common law systems you have increasing reliance on statutory law while civil law systems increasingly make use of precedents. Still, the basic principles remain.

Re: GDPR: Don't Panic

#158
post #47

Earlier quoted context omitted.

Do you have any experience with a Eu country internet regulatory service? I have experience with the CNIL (The french one), and they were helpfull and yes, good-natured. Part of our demand to be able to host data from hospital was drafted with their help, when they had no legal obligation to help us. A friend who work in a legal/tech startup also had good experience with them, and i don't know anybody who ever had a…

You seem to have misunderstood my comment. I was saying that from a legal complience perspective, the notion that the regulatary body is "good-natured" is meaningless. You have to comply with ever letter of the GDPR, you can't just do most of it, or interpret it loosely, and say "oh but they are good-natured people they will understand.". Legal complience doesn't work like that AT ALL!

No, but legal compliance in most of the EU doesn't work by slapping huge fines on people either - first you are told there is a problem and you'll be given a chance and maybe assistance to become compliant.

Re: GDPR: Don't Panic

#159

There's currently no case law surrounding GDPR. Moreover, some elements of the GDPR are up for interpretation. People are rightfully concerned. > "This post is an attempt to calm the nerves of those that feel that the(ir) world is about to come to an end" This post is actually a single person's viewpoint, a mere speculation of how things may or may not turn out to be. Your mileage may vary.

The GDPR is not completely new, though; it's a reformulation and extension of the existing Data Protection Directive, which was implemented back in 1995.

Re: GDPR: Don't Panic

#160
> this particular one has the interesting side effect of causing mass hysteria in the otherwise rational tech sector.

* Y2K

* Dot Com hysteria

* Dot Com crash hysteria

* AWS outages

* Will robots replace us ?

* Will Microsoft crush me ?

* Will Google crush me ?

* I just raised £30M series A, where my Aeron at

* Nosql means I can throw away everything I knew about databases

* Web first

* Mobile first

* XML everywhere

* OO everywhere

* Javascript everywhere

* AI everywhere

Where is the evidence for rational behaviour ?

Post reply on HN