Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

171–180 of 833 posts

Re: GDPR: Don't Panic

#171

This is just an author wishlist and not the reality. I especially find the "clearing house" fantasy amusing. How he thinks this house of bureaucrats will be able to judge that John Does complaint has any merit?

How he thinks this house of bureaucrats will be able to judge that John Does complaint has any merit?

The same way judges can throw out a case without going to trial. Checking if the complaint makes sense, if it represents an actual violation as described, etc. Anyone dealing with the public knows that a huge chunk of the complaints don't even pass that bar.

Re: GDPR: Don't Panic

#172
post #132

This is just an author wishlist and not the reality. I especially find the "clearing house" fantasy amusing. How he thinks this house of bureaucrats will be able to judge that John Does complaint has any merit?

Plus it gives easy access to the government to peek at your data without any significant clause. Your data are theirs too now.

That's not how it works. They don't send a guy to look at your databases.

Re: GDPR: Don't Panic

#173
Clearly an emotional topic. The fact remains, GDPR is a well-meaning but fuzzy law, with implications that cannot be foreseen at this point in time.

To remove some of the uncertainty and automate some of the compliance steps, we built a data discovery AI tech that scans corporate data to answer:

* "Do we even store personal information?"

* "Where do we keep it?"

* "How do we make sure PII is consistently stored only in the designated places?"

This may seem trivial to a micro-business that runs on a handful of database tables, which I think is where the author is coming from. But for larger companies, even understanding what's where and why (backups? emails? cloud storages?) is a highly non-trivial—if ultimately rewarding—endeavour.

Re: GDPR: Don't Panic

#174

There's currently no case law surrounding GDPR. Moreover, some elements of the GDPR are up for interpretation. People are rightfully concerned. > "This post is an attempt to calm the nerves of those that feel that the(ir) world is about to come to an end" This post is actually a single person's viewpoint, a mere speculation of how things may or may not turn out to be. Your mileage may vary.

The GDPR is not completely new, though; it's a reformulation and extension of the existing Data Protection Directive, which was implemented back in 1995.

For people and businesses in the EEA, the GDPR is much less of a change, because we already had to comply with data protection law. The rest of the world may be less prepared.

Re: GDPR: Don't Panic

#175

For those of you understandably intimidated by the GDPR regulations themselves, here's a good summary in plain English: https://blog.varonis.com/gdpr-requirements-list-in-plain-eng... The UK's ICO also has a good structured summary: https://ico.org.uk/for-organisations/guide-to-the-general-da... In general I agree with the sentiments in this article. I've probably spent a total of three to four days reading around th…

> I don't really see what's special about this law

The key change is the fairly explicit punishments and apparent intent to hand them out for non-compliance. A lot of older regulations get considered by companies but the issues relegated, officially or otherwise, to "yeah, we'll apologise and fix that when someone notices" which might not be a good way to manage the risk management after next Friday.

> ... might feel like "I run a small site on a Digital Ocean droplet and I'm at risk of a €2m fine out of the blue." But that doesn't make it true.

Exactly. A lot of the unhelpful hysteria is being drummed up by consulting companies trying to sell there services to help others assess and/or manage their GDPR compliance: they are stoking the fears to improve sales.

The rest is coming from people who don't want to lose control of some of what they consider to be _their_ data. From a business perspective this is usually "I've collected it or pad for it, I should be able to keep it / sell it / use it, this is unfair, wa waa waaaaaa" and from a technical perspective many of us data people have flinch reactions to any idea of hard-delete or un-rollback-able update operations (they are not really impossible to rollback of course, anyone sensible is building considerations for backup retention policies into their procedures, but rolling back is less likely to be simple and can only be done during that retention window).

Re: GDPR: Don't Panic

#176

For those of you understandably intimidated by the GDPR regulations themselves, here's a good summary in plain English: https://blog.varonis.com/gdpr-requirements-list-in-plain-eng... The UK's ICO also has a good structured summary: https://ico.org.uk/for-organisations/guide-to-the-general-da... In general I agree with the sentiments in this article. I've probably spent a total of three to four days reading around th…

I am concerned that the effect of this legislation on the private individual is the opposite of the stated intention.

People are being forced to sign agreements which jeopardise the natural rights to their data which they would otherwise have.

One example: a friend who has a very pretty daughter was asked by her school to give them the right to film her and to use any and all such recordings as they see fit for 50 years even after she leaves the school.

This feels very wrong on just about all the conceivable levels.

Re: GDPR: Don't Panic

#178
post #120

Earlier quoted context omitted.

It is highly unlikely that a lot of requests will "sink" your company. As per the GDPR, you have a month to respond to requests and you can extend this period by two more months by telling the user that you need more time to process their request. (See article 12 for reference)

If 10% of the members of my website request a GDPR, then my website will no longer exist. The processing time for that would be a decade.

You mean request to be forgotten? Are you seriously lacking an automated removal process if you have more than a thousand users and also can't keep it in a three month deadline? Oor is it collecting so much data that you cannot just send it all to the requestee?

If it would take a decade, then it is a broken business that should cease to exist as it is doing something illegal with the collected data. What kind of business is it?

Re: GDPR: Don't Panic

#179

Earlier quoted context omitted.

Perhaps something similar to the supersuccesful EU "cookie law" where a website could ask you on your first visit if you are an EU citizen. Wait, or is it EU residents and not just citizens? Be sure to get that correct.

EU residents in the EU, EU citizens worldwide.

No, there's nothing in the law about EU citizens. It's only about people in the EU.

Re: GDPR: Don't Panic

#180

This is no hysteria. Depending on where your company is located the sueing risk is really high. E.g. in countries like Germany there is a whole industry which lives from sueing companies and people and I can imagine that GDPR will open a whole new sueing market there. In other countries like Austria you get first warned and then sued on big GDPR violations which is a much better solution. So it all depends.

From a German perspective not much has changed: The core concepts "as minimal data collection as possible" & opt-in for more, the right to ask which data a company has about you and the right to make them delete it are established law in Germany since at least 2009 if not 1983.
Post reply on HN