Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

191–200 of 833 posts

Re: GDPR: Don't Panic

#191
post #169

This is how I understand the GDPR: You cannot store a users personal data like IP or cookie id unless you have consent from the user. I expect that nobody will comply with this. Smaller companies seem to think GDPR is something they can fix by changing the legalese in their impressum and privacy policy. "Yet another trip to the impressum generator". Bigger companies seem to pretend they misunderstand the GDPR. I got…

> You cannot store a users personal data like IP or cookie id unless you have consent from the user.

This isn't true; there's a list of reasons you can keep information and "with consent" is one of them, "legitimate business need" another: https://ico.org.uk/for-organisations/guide-to-the-general-da...

But: "However, an individual always has the right to object to processing for the purposes of direct marketing, whatever lawful basis applies."

So: you can store IP addresses as part of your information security needs, but not turn round and use them for direct marketing. (I'm not sure if web advertising counts as "direct marketing" here)

Re: GDPR: Don't Panic

#192

Earlier quoted context omitted.

The DPA (Datatilsynet) in Denmark operates in the exact way stated in the article. I've fairly sure it's the same in Sweden, Germany, UK, and most of the EU. It is in stark contrast to the US. I'm not going to link cases, because they're in Danish. They are available from their webpage, and the most resent ones are linked on the frontpage. The last few cases large companies was not in compliance and the didn't get a…

That's supernice for you in supernice Denmark. Now what about all the other EU countries? What about in 5 years time if things become less supernice. 10 years time?

I know it's kind of hard to imagine coming from a US perspective, but it's "supernice" as you say for pretty much everyone in pretty much every EU country. Based on decades of precedent behaviour.

Re: GDPR: Don't Panic

#193

Earlier quoted context omitted.

Completely agree with everything you list, and would add that 6. you can't force a user to give up privacy in order to get some other benefit, e.g. you can't offer to unlock some feature in return for more tracking

Example: How do you ask user for a permission to log access logs (which contain IP address) in the server, so that you can detect spam, ddos and other attacks? How do you store that consent information and what do you do if user doesn't consent? What do you do if user connecting from given IP address wants you to send him data you have collected about him. If people share IP addresses how do you know which log data i…

> How do you ask user for a permission

Why do you think permission is required?

Re: GDPR: Don't Panic

#194
post #120

Earlier quoted context omitted.

It is highly unlikely that a lot of requests will "sink" your company. As per the GDPR, you have a month to respond to requests and you can extend this period by two more months by telling the user that you need more time to process their request. (See article 12 for reference)

If 10% of the members of my website request a GDPR, then my website will no longer exist. The processing time for that would be a decade.

If you have a lot of “members” you obviously provide the services by the automated process. Obviously the request processing could also be mostly automatic.

Re: GDPR: Don't Panic

#195
post #169

This is how I understand the GDPR: You cannot store a users personal data like IP or cookie id unless you have consent from the user. I expect that nobody will comply with this. Smaller companies seem to think GDPR is something they can fix by changing the legalese in their impressum and privacy policy. "Yet another trip to the impressum generator". Bigger companies seem to pretend they misunderstand the GDPR. I got…

Why not just not store these things at all? If you have accounts, you get to directly comply anyway. Stop being drunk on cookies.

If you're talking about tracking cookies from an ad company, you better mention them in the privacy policy.

Re: GDPR: Don't Panic

#196
post #160

> this particular one has the interesting side effect of causing mass hysteria in the otherwise rational tech sector. * Y2K * Dot Com hysteria * Dot Com crash hysteria * AWS outages * Will robots replace us ? * Will Microsoft crush me ? * Will Google crush me ? * I just raised £30M series A, where my Aeron at * Nosql means I can throw away everything I knew about databases * Web first * Mobile first * XML everywhere…

Y2K is one rare example where all the panic actually got the problem fixed. The dotcom crash was definitely real with huge job losses too.

Re: GDPR: Don't Panic

#197
post #114

Earlier quoted context omitted.

You are transposing your like of certain EU institutions (human rights regulations) and grafting them onto this legislation. This isn't how it works, not least because there has been no case-law yet, so we have no idea how it will be interpreted. Therefore a legal compliance unit has no choice but to follow GDPR the letter, which is hugely difficult and bureaucratic. The notion that they are "good-natured" is meaning…

As mentioned elsewhere, these regulators have been operating for a very long time. Even when dealing with the whole Facebook / Cambridge Analytica they're moving quite slowly. There have been various legal changes regarding privacy in the past. E.g. for The Netherlands it is not allowed to have a checkbox on by default to sign up to a mailing list. There's a fine if you don't abide and this fine can be very hefty. In…

The substance of this line of criticism is that yes, it's probably going to be fine. But if it's not, they can fine you at 4% of global turnover. They probably won't, but they literally can. "I read on a blog that they'd be nice and send me a warning first" gets you exactly nowhere in court ("very well, but what did your lawyer tell you?"). The article praises the GDPR for having teeth -- being timid can be something you are because that's your nature, or it can be something your are because you don't have teeth.

This is what risk is. Absolutely, don't panic. But responsibly managing risk means considering the 100% real and existing option of regulators abandoning their previous caution and trying out their new teeth. Perhaps they get reined in, but perhaps that takes 10 years, or perhaps it turns out to be politically convenient not to rein them in a all. There are 28 EU countries, so 28 regulators, only one ambitious rising star at one of which need to "break bad".

Yes, I agree that this is probably a very small risk. But having a calm and correct view of the fact that there is a risk is 100% the right move here. Something like every other lawyer in Europe is worried about this right now, and do think it's a bit of a big deal. Don't panic, but take the advice of a non-lawyer's blog over your actual lawyer's at your own extreme peril.

Re: GDPR: Don't Panic

#198
post #145

Earlier quoted context omitted.

Well, lots of ends open to interpretation, and $20 mln fine - so obviously nothing to care about! Hysteria!

Maximum possible fine for repeated worst possible violation after ignoring previous attempts at regulation and not making changes after previous smaller fines. It's not a minimum.

It takes time, and real money to be compliant, and getting slow on this quite plausibly can make one a repeat offender. You can, of course, say "don't be slow then", however, when for an out-of-EU entity (be it biz, or NGO) simple math doesn't show it is worth the effort, then it makes perfect sense to stop offering services to EU. Which is a side effect of the legislation. OP apparently understands it puts GDPR in a bad light, so he says about "overreaction" in every topic related, and this post is likely comes as the response to the latest one.

Re: GDPR: Don't Panic

#199

> I was actually surprised by how easy it is to read it there's a whole two hundred post debate around here whether ip are or aren't pii on their own, with the wast majority holding the wrong position. there's a whole branch of gdpr that people aren't considering, which is not related to software but to your business (i.e. your mail calendar). you also need a privacy policy if you are receiving phone calls. did you k…

No, people were correctly answering the specific question: is an IP address on its own personal data? (No, it can't be used to identify a natural person).

THe problem is that it's a stupid question. No-one has just IP addresses, they have a mix of data. If you can combine the IP address with anything else to identify a natural person it becomes personal data.

Re: GDPR: Don't Panic

#200
post #132

Earlier quoted context omitted.

Plus it gives easy access to the government to peek at your data without any significant clause. Your data are theirs too now.

That's not how it works. They don't send a guy to look at your databases.

So how do they know if the response with the data a user requests, are all we've got about them, and if indeed where stored the proper way?
Post reply on HN