Live data from Hacker News

GDPR Hall of Shame

gdprhallofshame.com

181–190 of 192 posts

Re: GDPR Hall of Shame

#181

Earlier quoted context omitted.

I must admit, even as a critic of the GDPR in some respects, as an individual I am hoping that its heavy-handed approach will mean I can buy everyday things again without having spyware, telemetry, and so on coming as standard. I don't want a "smart" phone or a "smart" TV or a "connected" car, where the scare quotes denote entirely unnecessary invasion of privacy and/or security and safety risks. I buy a phone to com…

Then just buy older stuff nobody says you need a smartphone.

Every month it gets harder to buy a non-smart TV. They still exist, but mostly one ends up buying a smart TV and just never logging into it.

Re: GDPR Hall of Shame

#182

Earlier quoted context omitted.

The trouble with the GDPR is that there is so much ambiguity in even quite basic areas of the regulations and the official guidance so far that any formal opinion you get from lawyers, consultants, regulators and the like is riddled with vague terms like "reasonable", "legitimate", "proportionate" and "balanced". It's advice that doesn't actually answer any of the important questions like "Am I compliant?" or "What s…

>riddled with vague terms like "reasonable", "legitimate", "proportionate" and "balanced" You could be describing a very large proportion of laws. To pick a random example, I'll go with the Road Traffic Act 1991 (England and Wales). It is an offence under this act to drive a mechanically propelled vehicle dangerously on a public road. The definition of dangerous driving is: a) the way he drives falls far below what w…

I respectfully disagree with your example. We have very specific standards required for competent and safe driving, and in addition to the laws, there is well-established official practical guidance available in the form of the Highway Code. We have a regime of qualified instructors and examiners to guide and assess newcomers, and everyone has to pass a test to demonstrate their competence and understanding before being allowed out on the road independently. And then we're talking about criminal law, which means the burden of proof is heavily on the prosecution, you're going to be in court, and for more serious cases there is going to be a jury involved. And even then you have to fall far below the expected standard in a way that is obvious to someone who doesn't. None of those things applies in the context of GDPR.

Re: GDPR Hall of Shame

#183

Earlier quoted context omitted.

I must admit, even as a critic of the GDPR in some respects, as an individual I am hoping that its heavy-handed approach will mean I can buy everyday things again without having spyware, telemetry, and so on coming as standard. I don't want a "smart" phone or a "smart" TV or a "connected" car, where the scare quotes denote entirely unnecessary invasion of privacy and/or security and safety risks. I buy a phone to com…

Then just buy older stuff nobody says you need a smartphone.

Have you tried buying a non-smart TV or a non-connected car recently? Or even a feature phone that is basic in features but good quality? I do have quite a few devices from just before the madness became almost inescapable, but it has become increasingly difficult to get hold of these things in recent years. Aside from the sales and marketing aspects, there are other pressures that are forcing older models into obsolescence prematurely, such as changing encodings and DRM mechanisms for video, changing standards for wireless communications, and environmental and safety issues that drive older cars off the roads.

Re: GDPR Hall of Shame

#184

Could somebody help me understand the criticism in this article of companies like Instapaper blocking EU users? When you face fines of up to 20M EUR, you’re not going to take on that liability if you have a choice. Most companies outside the EU will eventually block EU traffic. GDPR is just too big of a liability. It has nothing to do with “selling user data” or bad intentions with user privacy. I won’t take EU traff…

Blocking EU users temporarily doesn't remove the need to comply - they're still holding data from these users.

Re: GDPR Hall of Shame

#185

Earlier quoted context omitted.

The trouble with the GDPR is that there is so much ambiguity in even quite basic areas of the regulations and the official guidance so far that any formal opinion you get from lawyers, consultants, regulators and the like is riddled with vague terms like "reasonable", "legitimate", "proportionate" and "balanced". It's advice that doesn't actually answer any of the important questions like "Am I compliant?" or "What s…

>riddled with vague terms like "reasonable", "legitimate", "proportionate" and "balanced" You could be describing a very large proportion of laws. To pick a random example, I'll go with the Road Traffic Act 1991 (England and Wales). It is an offence under this act to drive a mechanically propelled vehicle dangerously on a public road. The definition of dangerous driving is: a) the way he drives falls far below what w…

[deleted]

Re: GDPR Hall of Shame

#186
post #29
post #10

Earlier quoted context omitted.

Why? This seems like good behavior. They're original product is supported by a business model that relies on user data. Now they are offering a similar product that doesn't make money off of user data but instead charges the user. I am all for the GPDR, but the regulations don't say you can't suck up all user data _and_ you still have to provide your service for free/discounted

So you're saying user's data is worth $23052 per year?

[deleted]

Re: GDPR Hall of Shame

#187
post #147

Earlier quoted context omitted.

I think that's intentional as it massively increases the risk of doing something negative for the end user and leaves loopholes uncertain and prone to interpretation. It will forces businesses to stay well clear of the line or pack up and go home. And that's not a bad thing. Also it stops a whole legal and compliance industry appearing in the grey zone as no one wants to abstract liability.

It will forces businesses to stay well clear of the line or pack up and go home. And that's not a bad thing. I'm not so sure. No-one knows where the line is, so many organisations can only be sure they're staying well clear by stopping all kinds of legitimate, reasonable data processing, which is throwing the baby out with the bathwater. An alternative, which I've seen quite a few small organisations and individuals…

Legitimate and reasonable data processing is just that: it's obviously compliant. If there is any doubt, it's excessive and careless data processing, even if not illegal and without malicious intent.

So there is no valuable baby that could be thrown out with the bathwater, and a well-behaved company has little or no bathwater to begin with.

Re: GDPR Hall of Shame

#188

Earlier quoted context omitted.

It will forces businesses to stay well clear of the line or pack up and go home. And that's not a bad thing. I'm not so sure. No-one knows where the line is, so many organisations can only be sure they're staying well clear by stopping all kinds of legitimate, reasonable data processing, which is throwing the baby out with the bathwater. An alternative, which I've seen quite a few small organisations and individuals…

Legitimate and reasonable data processing is just that: it's obviously compliant. If there is any doubt, it's excessive and careless data processing, even if not illegal and without malicious intent. So there is no valuable baby that could be thrown out with the bathwater, and a well-behaved company has little or no bathwater to begin with.

Legitimate and reasonable data processing is just that: it's obviously compliant. If there is any doubt, it's excessive and careless data processing, even if not illegal and without malicious intent.

No, it isn't. Sorry, you can't just hand-wave the whole issue away that easily. If this were all so obvious, we wouldn't keep having these conversations, where even people who have been looking into this for months and taken real legal advice are still in doubt about what specific actions they can or must take to be compliant.

Re: GDPR Hall of Shame

#189

Earlier quoted context omitted.

Legitimate and reasonable data processing is just that: it's obviously compliant. If there is any doubt, it's excessive and careless data processing, even if not illegal and without malicious intent. So there is no valuable baby that could be thrown out with the bathwater, and a well-behaved company has little or no bathwater to begin with.

Legitimate and reasonable data processing is just that: it's obviously compliant. If there is any doubt, it's excessive and careless data processing, even if not illegal and without malicious intent. No, it isn't. Sorry, you can't just hand-wave the whole issue away that easily. If this were all so obvious, we wouldn't keep having these conversations, where even people who have been looking into this for months and t…

I should have been more explicit about my point: GDPR compliance is easy and inexpensive for restrained good companies that care about privacy, troublesome and expensive only for companies that behave inappropriately, and an existential threat only for true scum.

You are simply being forced to behave like you should have been behaving from the beginning of your online presence.

Re: GDPR Hall of Shame

#190

Earlier quoted context omitted.

It will forces businesses to stay well clear of the line or pack up and go home. And that's not a bad thing. I'm not so sure. No-one knows where the line is, so many organisations can only be sure they're staying well clear by stopping all kinds of legitimate, reasonable data processing, which is throwing the baby out with the bathwater. An alternative, which I've seen quite a few small organisations and individuals…

Legitimate and reasonable data processing is just that: it's obviously compliant. If there is any doubt, it's excessive and careless data processing, even if not illegal and without malicious intent. So there is no valuable baby that could be thrown out with the bathwater, and a well-behaved company has little or no bathwater to begin with.

That is absolutely meaningless and opens up every business to constant unrelenting litigation. Your definition of obvious is not the same as someone else.
Post reply on HN