Live data from Hacker News

Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

politico.eu

161–170 of 190 posts

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#161
So cookie banners go first? As an obsolote "requirement" when all that tracking will be finaly banned? Right ? Just like paper journals - they don't do any identify-your-page-flipper...

And employer will be finally allowed to know his employee name and address?? Without additional paper trail? No, they won't allow that, it will be to sane.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#162

Earlier quoted context omitted.

The cookie banners aren't worthless. The websites presenting cookie banners either don't know the law, or are engaged in spyware shit. You don't need a cookie banner if you need it to provide a service that the user expects (e.g., saving settings, login). As an EU citizen, I'm not concerned about your need to observe my behaviour or to prevent ad-click fraud. What I care about is websites sharing my navigation histor…

Cookies aren't spyware. If you want to disable them, disable them in your browser. It is something you send to the server. Not something they do on their end. Surely people here are aware of that?

The issue is when you want to be able to stay logged in to a site, but do not want Google track you across the internet. Cookies do not differentiate between what they are used for, so sites have to make it clear only if they are going to track you. You do NOT need a cookie banner if you're not tracking your users

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#163
post #35

Earlier quoted context omitted.

I don't see why small organizations should get to be more careless with my personal data than anybody else. The value of my privacy doesn't change just because of the size of the company.

It isn't "your data". Which pages you have viewed on my website is my data. It relates to you but is does not belong to you. You don't have any privacy right to control data that belongs to other people and happens to relate to you. Privacy is about the state needing a warrant to enter your home and search it or to wiretap you. The idea it has anything to do with information you GIVE to websites by visiting them is a…

I'm glad the EU and most Europeans disagree with you. Because this take is just wrong on so many levels and I'm not sure where even to begin.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#164
> "the simplification plan will focus on reporting requirements for organizations with less than 500 people"

I consider this extremely bad! It should be based on revenue, not people.

I can imagine extremely big data trading companies with less than 500 people. I can even imagine Meta/Facebook doing various employee redistribution shenanigans and managing to fit inside that limit.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#165

Earlier quoted context omitted.

> I expect the plumber to instead pay someone This is fundamentally wrong expectation. To preserve the spirit of EU charter one does not need the law where every business engaging with customers online has to pay a compliance tax to another medieval guild of experts.

Do you do your own structural engineering or do you pay someone to do it who is qualified to do so in the EU? Structural engineering compliance is a medieval guild of experts, is it not? Do you practice your own medicine in the EU or do you pay someone to do it? Medical compliance is a medieval guild of experts, is it not?

What are you doing is a classical straw man argument. I‘m not disputing that plumbers, doctors etc should be aware of their professional regulations. However certain regulations aren’t job-specific and work like tax, e.g. if you look at notary costs related to registration of business in Germany. Regulations like GDPR apply to business environment in general and they have to be designed so that the costs of compliance and risks of non-compliance are minimized. They are supposed to be followed by non-professionals, because privacy is not a job of DPO, it’s everyone’s concern. What you fail to understand in my comments is that part. I’m not disputing the usefulness of GDPR. I‘m saying that rather than strangling businesses with high compliance costs and complaining that everyone is choosing to show cookie banner instead of not tracking, we should look at how to avoid this nonsense. As a matter of fact, non-compliance is rife, people do cut corners and take the risk, because DPAs cannot catch or punish everyone. GDPR is suppressing the most egregious behavior, but it certainly not working as expected. It needs some careful reform.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#166
post #163

Earlier quoted context omitted.

It isn't "your data". Which pages you have viewed on my website is my data. It relates to you but is does not belong to you. You don't have any privacy right to control data that belongs to other people and happens to relate to you. Privacy is about the state needing a warrant to enter your home and search it or to wiretap you. The idea it has anything to do with information you GIVE to websites by visiting them is a…

I'm glad the EU and most Europeans disagree with you. Because this take is just wrong on so many levels and I'm not sure where even to begin.

ie. you have an instant emotional reaction but no actual arguments.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#167

Earlier quoted context omitted.

Do you do your own structural engineering or do you pay someone to do it who is qualified to do so in the EU? Structural engineering compliance is a medieval guild of experts, is it not? Do you practice your own medicine in the EU or do you pay someone to do it? Medical compliance is a medieval guild of experts, is it not?

What are you doing is a classical straw man argument. I‘m not disputing that plumbers, doctors etc should be aware of their professional regulations. However certain regulations aren’t job-specific and work like tax, e.g. if you look at notary costs related to registration of business in Germany. Regulations like GDPR apply to business environment in general and they have to be designed so that the costs of complianc…

> However certain regulations aren’t job-specific and work like tax, e.g. if you look at notary costs related to registration of business in Germany.

This is not that. You’re making it sound like every business has to jump through all of these hoops as a matter of doing business. You know how to not be bound by GDPR? Don’t bother storing sketchy cookie data or PII. The plumber in your example could just… not do that and not have to worry about compliance. It’s only but for the plumber choosing to store that data that they opt to be bound by the regulation. It’s not a requirement for them to operate. If the business feels like they need to store the nuclear waste, then I need to know that they are storing it properly. They could just not take in and store the nuclear waste and then there’s no compliance burden. 9 times out of 10 they don’t need it to transact their business anyway, and the tenth business probably only exists but for the sketchy data.

In the end we have arrived at the same conclusion: probably the regulation itself, the baby, has some dirty bath water. Any regulatory framework of any significant complexity does, especially a landmark first of its kind in scope regulation in the world. So we should not toss both out. We should try to get rid of just the bath water.

With above said, the plumber is not absolved here. Why did they need to store my PII again? I very much value the fact that they have to think about and answer that question. So whatever improvement should just streamline that process and not get rid of it.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#168
I see lots of comments supporting it but I can see they are mostly from the business side. What does "simplification" mean for users? I'm expecting companies to be given way more room for exploiting user consent for shady data collection practices.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#169

Earlier quoted context omitted.

What are you doing is a classical straw man argument. I‘m not disputing that plumbers, doctors etc should be aware of their professional regulations. However certain regulations aren’t job-specific and work like tax, e.g. if you look at notary costs related to registration of business in Germany. Regulations like GDPR apply to business environment in general and they have to be designed so that the costs of complianc…

> However certain regulations aren’t job-specific and work like tax, e.g. if you look at notary costs related to registration of business in Germany. This is not that. You’re making it sound like every business has to jump through all of these hoops as a matter of doing business. You know how to not be bound by GDPR? Don’t bother storing sketchy cookie data or PII. The plumber in your example could just… not do that…

Can you please read my comments in this thread in full and not just pick some parts of them?

I already explained that most businesses are not experts in privacy and usually become non-compliant accidentally, without malicious intent. If a plumber goes to some advertisement platform to promote their services online, they are not making fully informed decision with regards to privacy implications. They buy promises of lower CACs. They do not buy the storage of PII, neither they fully understand that targeted advertisement involves storage and processing of PII. And regulation requires them to either fully understand the process or spend money on external consultant. That's stupid: GDPR moved the responsibility to protect human rights from those who aggregate a lot of data to a little guy. What really should have been done is requirement for MarTech to support "Do not track" on protocol level and risk being fined or banned from EU. It does not make sense to ask users again and again on different websites if they are ok with tracking by FancyMarTech LLC, when those users already gave the answer somewhere.

It's just one example. And then there's a case with storing PII in Google Spreadsheet: everyone does that. Nobody mentions that in their privacy policy, even if DPO is involved. And probably they should not. Regulation should also consider the public risk. If one of those millions spreadsheets with a hundred names is leaked, let's fine the owner, sure. But let's not make a big compliance process for every owner of those millions spreadsheets. Let's say: Dear Google, if you want to work in EU, you cannot share the data of EU users with NSA or anyone. Keep it safe. Figure this out, we don't care how. We really should put 99% of compliance burden on processors and spare controllers.

Post reply on HN