Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

161–170 of 833 posts

Re: GDPR: Don't Panic

#161

This is no hysteria. Depending on where your company is located the sueing risk is really high. E.g. in countries like Germany there is a whole industry which lives from sueing companies and people and I can imagine that GDPR will open a whole new sueing market there. In other countries like Austria you get first warned and then sued on big GDPR violations which is a much better solution. So it all depends.

As per the article, GDPR does not enable you to sue the company.

> What the GDPR allows private individuals to do is to contact their regulators and to complain if you decide to ignore their requests.

The individual will not receive a payout from a GDPR violation.

Re: GDPR: Don't Panic

#162
> in the spirit of the good natured enforcers at the various data protection agencies in Europe

Is this serious? Why would we assume enforcers to be good natured if they benefit from fines. Or to assume they would stay good natured, even if you have the most perfect humans there now.

It's far more likely that the EU is creating tools to prevent disruption and manipulate markets. The template will likely be followed elsewhere, effectively elevating the state's data collection abilities over all other organizations.

Note, Bitcoin does not seem compatible with their laws.

Re: GDPR: Don't Panic

#164
post #64

Earlier quoted context omitted.

Not an alternative - but the only obvious defence is to do the right thing, and delete data as soon as you have completed processing. e.g. delete those interview notes the second you have declined the candidate.

That's ridiculous. Has anyone in this thread actually ever run a recruiting operation? I have. There's no way we will be deleting interview notes the moment a candidate is rejected. For one, we have to be able to prove later that we didn't reject based on grounds of discrimination (other regulations). But you also need the ability to review what your interviewers are doing to ensure consistency and quality of assessm…

The onyl change you need to make is to be able to delete information about criminal offences when those convictions become spent. Arguably that's not a new requirement, but GDPR does make it clearer.

> I have argued above that I legitimately need interview notes for the operation of my business.

That's the point. You're keeping data to comply with a law (Equality laws) or for legitimate reasons, and so you don't need permission and you don't need to delete it when asked.

https://gdpr-info.eu/art-6-gdpr/

> Processing shall be lawful only if and to the extent that at least one of the following applies:

> processing is necessary for compliance with a legal obligation to which the controller is subject;

> processing is necessary in order to protect the vital interests of the data subject or of another natural person;

> processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;

> processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.

Any of these would suit.

https://gdpr-info.eu/art-17-gdpr/

Re: GDPR: Don't Panic

#165

Earlier quoted context omitted.

Completely agree with everything you list, and would add that 6. you can't force a user to give up privacy in order to get some other benefit, e.g. you can't offer to unlock some feature in return for more tracking

Example: How do you ask user for a permission to log access logs (which contain IP address) in the server, so that you can detect spam, ddos and other attacks? How do you store that consent information and what do you do if user doesn't consent? What do you do if user connecting from given IP address wants you to send him data you have collected about him. If people share IP addresses how do you know which log data i…

Some entity runs a webserver. This entity has a legitimate business purpose in retaining access logs for e.g. 3 months for e.g. spam and security reasons. This entity just has to document that.

This entity can allow a 3rd party service to access these logs so that 3rd party can do whatever needs to be done if it is within the reasons the entity gave for having the data.

What neither can do is go use that data for anything other than the said purposes.

And if the given reasons are gratuitous and somehow the regulators notice, expect to get a nastygram and have to comply or face fines.

Basically what you can't do is collect data for longer than you have a legitimate need for, or cash-in and sell data you've collected. Basically, all said and done, just don't be sleezy and you'll be ok.

Re: GDPR: Don't Panic

#166

> in the spirit of the good natured enforcers at the various data protection agencies in Europe Is this serious? Why would we assume enforcers to be good natured if they benefit from fines. Or to assume they would stay good natured, even if you have the most perfect humans there now. It's far more likely that the EU is creating tools to prevent disruption and manipulate markets. The template will likely be followed e…

Yes I'm sure enforcers are looking to fine Bitcoin.

Re: GDPR: Don't Panic

#167
post #145

Earlier quoted context omitted.

Well, lots of ends open to interpretation, and $20 mln fine - so obviously nothing to care about! Hysteria!

Maximum possible fine for repeated worst possible violation after ignoring previous attempts at regulation and not making changes after previous smaller fines. It's not a minimum.

I think this is a common misinterpretation though because of the lanauge - that the maximum fine is actually the minimum, because the figures that are talked about are "€20m or 4% of global turnover, whichever is the greatest." It's the emphasis on "the greatest" that has an undercurrent of "we're going to fine you the maximum of these two numbers."

Re: GDPR: Don't Panic

#168

Here in UK I have been receiving about 5-10 emails a day from various companies - most of whom I don't remember - telling me I need to sign up again so they can keep my details and keep spamming me. Fantastic.

I will be interested to see if the same companies do actually stop emailing me and delete my information after I ignore their request to opt in!

I'm sure there are plenty of bad actors who will keep spamming regardless. Thankfully those ones seldom get through my spam filter - so barely trouble my consciousness.

Re: GDPR: Don't Panic

#169
This is how I understand the GDPR:

    You cannot store a users personal data like IP
    or cookie id unless you have consent from the user.
I expect that nobody will comply with this.

Smaller companies seem to think GDPR is something they can fix by changing the legalese in their impressum and privacy policy. "Yet another trip to the impressum generator".

Bigger companies seem to pretend they misunderstand the GDPR. I got emails and popups from Facebook, Twitter, Instagram etc informing me about all kinds of nonsense about how they changed their policies and asking me all kinds of unrelated questions about what kind of ads I want to see.

Not a single company asked me for permission to store my personal data.

Re: GDPR: Don't Panic

#170

There's certainly no need to panic. The article doesn't address that apart from mindless hysteria there are some very real issues with GDPR. It doesn't have to of course because as the title suggests it's more about dispelling panic than about giving concrete advice. However, many real-life problems seemingly haven't even been considered by legislative bodies. In GDPR support forums questions like these have been rou…

1) Respond to requests about removal of personal data, do not sell data, inform about data leaks and handle them, if outsourcing, check compliance.

2) Any item that is not legal there will be just void in court. You cannot be sued about an invalid legal policy, but only after breaking the law. The policies do not subsume law.

About the only thing you need to publish is which data is collected, how it is processed (and by whom if outsourced), for how long (if applicable) and how to remove it.

3) Uh, as usual complying to the law for PII handling?

4) Yes, if they are GDPR compliant. Make sure to put them in you privacy policy.

5) Yes, if the source is GDPR compliant.

Post reply on HN