Live data from Hacker News

GDPR Feels Useless

medium.com

21–30 of 35 posts

Re: GDPR Feels Useless

#21

Don't read this. There's so much misunderstanding in this article, I'd be surprised if any good discussion came from it. And refuting it would take ages. For example: > And apparently typing your name, age and other information is not consent. How is this supposed to work by the way? I give you my name but I don’t consent to you using it or remember it? The way it's phrased is misleading. If you need the data and are…

It's worth reading. It will remind you of the rule of law; that we all should follow the laws because it makes society better. You can speed your car down the road and there is no mechanism to prevent you from breaking the limit, but most people don't do this because they respect speeding laws and why they were created.

Same thing here. Yes GDPR has no mechanism to enforce these things. It's up to everyone to respect the law and enforce it upon themselves. If you don't respect laws, then you don't respect 'em, simple as that. Eventually, you will get caught.

Re: GDPR Feels Useless

#22
post #19

Earlier quoted context omitted.

That's the general issue with regulation, it protects the existing large players in a space by adding a higher barrier to entry for competitors. So now instead of hosting your own forum or website you'll use Squarespace or Discord or Disqus instead.

You can host your own forum. And if you do it as purely personal activity, then GDPR does not apply.

Is running a forum a purely personal activity? I'm not so sure. It certainly won't be if you have any third party services running on it.

Re: GDPR Feels Useless

#23
post #14

Earlier quoted context omitted.

Uh? Couldn't a hash be used for that?

According to our council, even encrypted or hashed data was still counted as PII as those are security measures, not privacy measures.

I mean, trust your council over some random guy on the internet (me), but I would seek a second opinion on this from a technilogically savvy lawyer.

There are absolutely implementations available that will allow you to have a hash, not tied to other data, sitting in your opt-out list that you than check other hashes against. No PII in the mix.

Re: GDPR Feels Useless

#25
post #17
post #5

I don't view GDPR to be quite as useless as the author does, but the point about the user having to protect their data themselves is spot on. GDPR only protects you against good actors that are under EU jurisdiction. Everyone else could very well be doing whatever they want with the data you leak. The EU can't fine a Chinese company if the Chinese company has no presence in the EU. Another thing the author doesn't me…

First of all, GDPR does not apply to personal sites. ( https://law.stackexchange.com/a/28086 - see current "in force" version of the directive: https://eur-lex.europa.eu/eli/reg/2016/679/oj see recital 18) > [...] GDPR sets a minimum amount of cost/effort to run a website [...] This is simply false. If you want to post something on the 'net, nothing changes. You want to count page downloads? (You know those old schoo…

>First of all, GDPR does not apply to personal sites.

And next to no websites actually fall under this exemption. Furthermore, simply to know that your website falls under this exemption comes with the cost. You must know that your website falls under this exemption, requiring you to know GDPR and/or requiring a lawyer to look it over (high cost).

>This is simply false. If you want to post something on the 'net, nothing changes.

Simply having to know what GDPR is, what it covers, and whether you fall under it has a cost. So the statement that nothing changes is patently false.

Also, I'm pretty sure that by default most software that serves websites would already put you under GDPR, because it collects IP addresses and they're considered personal data.

>Agreed. But small sites were always at the mercy of random script kiddies. They always lacked resources to properly handle updates/upgrades, security, data, end-of-life termination, etc.

So, because there were other limiting factors for them we might as well make it illegal to run such websites? I guess I can understand why the EU's tech sector is doing so poorly.

>Again, similarly, if you handle a lot of data you should be able to accurately take a stock of what kind of data you have about whom, hence the requirement to respond to these inquiries.

But it's not about that. It's "if you handle any data then you must constantly be available to tell users what data you have about them". This, ironically, puts people's data at risk, because suddenly you forced website owners to reply to phishing requests. What's the chance that every single website owner everywhere never gives out personal data to the wrong person? I would say that that chance is effectively zero.

Re: GDPR Feels Useless

#26

Don't read this. There's so much misunderstanding in this article, I'd be surprised if any good discussion came from it. And refuting it would take ages. For example: > And apparently typing your name, age and other information is not consent. How is this supposed to work by the way? I give you my name but I don’t consent to you using it or remember it? The way it's phrased is misleading. If you need the data and are…

You can't refute a "feeling" anyway as it is subjective.

I saw the headline and thought I'd verify my suspicion here in the comments (Confirmation Bias!) before spending my time on the article.

Re: GDPR Feels Useless

#27
post #17
post #5

I don't view GDPR to be quite as useless as the author does, but the point about the user having to protect their data themselves is spot on. GDPR only protects you against good actors that are under EU jurisdiction. Everyone else could very well be doing whatever they want with the data you leak. The EU can't fine a Chinese company if the Chinese company has no presence in the EU. Another thing the author doesn't me…

First of all, GDPR does not apply to personal sites. ( https://law.stackexchange.com/a/28086 - see current "in force" version of the directive: https://eur-lex.europa.eu/eli/reg/2016/679/oj see recital 18) > [...] GDPR sets a minimum amount of cost/effort to run a website [...] This is simply false. If you want to post something on the 'net, nothing changes. You want to count page downloads? (You know those old schoo…

>First of all, GDPR does not apply to personal sites

No, as I read it excludes sites that do not engage in economic or professional activity. It is specific about what personal means and it's definition is not necessarily the colloquial definition of personal.

So, as a layman, by my reading getting donations makes your site covered, running ads make it covered, allowing people to sell things makes it covered, people connecting for jobs makes it covered, using it as advertising for your professional career (ie: blog post that says you're looking for a job) makes it covered, etc.

Or maybe it doesn't cover those but then I'd need (and thus need to pay) a lawyer to know wouldn't I? Layers aren't cheap compared to the cost of modern web hosting.

Re: GDPR Feels Useless

#28
post #19

Earlier quoted context omitted.

That's the general issue with regulation, it protects the existing large players in a space by adding a higher barrier to entry for competitors. So now instead of hosting your own forum or website you'll use Squarespace or Discord or Disqus instead.

You can host your own forum. And if you do it as purely personal activity, then GDPR does not apply.

As I read it specifically doesn't cover things which are not economic activities and not professional activities. You running a website yourself and not as business may or may not fall into that. It is not necessarily the colloquial definition of personal.

A personal website may have donations, may have ads, may act as advertising for your professional career, may be used to find jobs for yourself, may be used by people to trade items to each other, etc, etc. Those may be covered by GDPR and without a lawyer (ie: money) I have no idea.

Re: GDPR Feels Useless

#29

This is just a weird article. > But do you know what data I have access to when you come on my website ? Well only your IP and some information about your computer and browser. That’s all. It's pretty well known by now that that's often more than enough to identify a specific user. "That's all" really undersells it. > It’s true I can create an ID and save it on your browser (I can do much more but we will stay focus)…

I’d ask similarly, when you enter the public sphere, does that give me the right to collect DNA samples you’ve “voluntarily” dropped on the floor, like in police shows? You abandon your privacy when you voluntarily expose yourself to the public, right?

I think the public is divided on the issue and have no consensus nor common language for matters of privacy.

Re: GDPR Feels Useless

#30
Interesting perspective and I can see some of the intent here, but it takes an odd slant to the issue. There are a few failures in logic here (random number becoming PII, only tracking on one browser, laws protecting you from getting robbed) that detract from the goal of GDPR which is to outline the user's digital rights, not define how data can be collected. GDPR does not define the technological methods because those will always be evolving, much like our understanding and expectations of data privacy will evolve. I agree that users need to educate themselves on how to protect their own data, but there is a ton of technology that they either aren't aware is being used, or simply don't understand. GDPR isn't perfect but it will help in the long run. Here is a summary of some of the details and how it will impact what developers need do as they architect software. Some companies will take it seriously, others won't. Then consumers may decide who to do business with. https://fusionauth.io/blog/2019/01/29/white-paper-developers...
Post reply on HN