Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

21–30 of 833 posts

Re: GDPR: Don't Panic

#21

There's currently no case law surrounding GDPR. Moreover, some elements of the GDPR are up for interpretation. People are rightfully concerned. > "This post is an attempt to calm the nerves of those that feel that the(ir) world is about to come to an end" This post is actually a single person's viewpoint, a mere speculation of how things may or may not turn out to be. Your mileage may vary.

On what experiences with EU bureaucracy do you base your statement?

Re: GDPR: Don't Panic

#22
Here in UK I have been receiving about 5-10 emails a day from various companies - most of whom I don't remember - telling me I need to sign up again so they can keep my details and keep spamming me.

Fantastic.

Re: GDPR: Don't Panic

#23

Exactly. People try to explain to me how it is impossible to comply and usually it turns out that it would be easy. I think the problem most of time that people misunderstanding the requirements or not reading GDPR (not even TLDR versions).

It is easy if they believe particular person's interpretation. But that doesn't mean they are right. People have huge problems with interpreting written word if it is not written without a room for interpretation and if you add to the mix bureaucrats that have targets to meet you'll see it will not be easy at all.

The only person who’s opinion you should worry about is your internal legal counsel’s. The nerds who try to carry on like this is a technical problem with a technical solution are so far off. It’s about beig able to argue and justify your interpretation - not how much you have gold plated your tech stack

Re: GDPR: Don't Panic

#24
Is the system of warnings and increasing fines described in the post a part of the law, or does one need to rely on the "spirit of the good natured enforcers" if they are unable (or unwilling) to immediately comply fully?

Re: GDPR: Don't Panic

#25

Exactly. People try to explain to me how it is impossible to comply and usually it turns out that it would be easy. I think the problem most of time that people misunderstanding the requirements or not reading GDPR (not even TLDR versions).

It is easy if they believe particular person's interpretation. But that doesn't mean they are right. People have huge problems with interpreting written word if it is not written without a room for interpretation and if you add to the mix bureaucrats that have targets to meet you'll see it will not be easy at all.

[deleted]

Re: GDPR: Don't Panic

#26
> I was actually surprised by how easy it is to read it

there's a whole two hundred post debate around here whether ip are or aren't pii on their own, with the wast majority holding the wrong position.

there's a whole branch of gdpr that people aren't considering, which is not related to software but to your business (i.e. your mail calendar). you also need a privacy policy if you are receiving phone calls. did you know that?

there's a whole bunch of implication on how liable you are about holding unwanted personal information, including unwanted medical personal information i.e. "hi I saw your gazebo renting service, I'm organizing an event but I am unable to walk due a permanent disability and requiring a ramp is present to access your gazebo, is that so?"

there is a huge surface area for uncertainty, up and including 'best practices' that are a constantly shifting target.

edit: to clarify the calendar part: if you have a meeting with someone, that links an identity with a location. that's why it's an issue, even without considering the address book, which is another issue by itself.

Re: GDPR: Don't Panic

#27
post #2

How does this affect people who aren't based in Europe?

Perhaps something similar to the supersuccesful EU "cookie law" where a website could ask you on your first visit if you are an EU citizen.

Wait, or is it EU residents and not just citizens? Be sure to get that correct.

Re: GDPR: Don't Panic

#28

Here in UK I have been receiving about 5-10 emails a day from various companies - most of whom I don't remember - telling me I need to sign up again so they can keep my details and keep spamming me. Fantastic.

I have the same experience. All those forgotten accounts. Now I can just go on and delete them.

Super basic stuff.

Re: GDPR: Don't Panic

#30
post #2

How does this affect people who aren't based in Europe?

I think many (most?) companies will implement these privacy policies across all of their users as it can be hard to determine whether a user is in the EU or not... so indirectly, this law might mean that everybody will finally have strong privacy guarantees (at least when it comes to companies of a meaningful size).

And as so often the EU will be the initiator of a world wide adoption of (semi) unified rules, as it was for USB charging, among other things.

It will naturally get a lot of flack and a few people/companies will make it their scapegoat as to deflect from them as usual, but that's - sadly - almost normal now.

Is it all good: no!

Is it a good start: yes!

Is it IMPOSSIBLE to comply: heck no, I'm working at a small Austrian company and we had to change almost nothing, as lo and behold, we have no desire to be a data kraken and tried to held the privacy of our customer and users always on a reasonable level. As we'd wish that others do with our data and use of service...

Post reply on HN