Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

201–210 of 833 posts

Re: GDPR: Don't Panic

#201
One question that I have thought about is how are foreigners supposed to learn about the GDPR's existence? If it wasn't for the fact that I spend more time on HN that I should I would never have heard of it. I doubt there are many businesses here in Australia that know about it.

Re: GDPR: Don't Panic

#202
post #71

Earlier quoted context omitted.

Geolocation, IP Lookup etc. You generally shouldn't care whether they're a resident in the EU, but just whether they are in EU or not. Remember GDPR doesn't cover any citizens from EU who aren't in EU.

I read that GDPR applies to EU residents. That means someone who is EU resident non necessarily could be browsing from the EU. For example when on holidays.

[deleted]

Re: GDPR: Don't Panic

#203

Earlier quoted context omitted.

Fair point about it being public bodies. But my point stands in terms of abuse of the system - the deluge didn't happen.

I have actually seen government agencies complain about being deluged by FOI requests, the cost of dealing with them etc. They mostly get ignored because on inspection the "deluge" of FOI requests tends to be from journalists digging for stories, and that's sort of what we want them to do. Also because the high cost of FOI responses tends to reflect messy and disorganised internal information systems rather than anyt…

> But GDPR enforcement is incentivised by large sums of money, for an organisation that is technically bankrupt.

What do you mean here? It seems to be about suggesting that GDPR is about getting the fine money? Elsewhere the law is quoted where it states the fine should be appropriate to be effective. So even if you don't trust this there's legal ground to back it up. Secondly, why is the EU technically bankrupt? Or is this a theoretical organization?

Appreciate some clarification because currently the sentence I quoted is too open to interpretation.

Re: GDPR: Don't Panic

#204
post #166

> in the spirit of the good natured enforcers at the various data protection agencies in Europe Is this serious? Why would we assume enforcers to be good natured if they benefit from fines. Or to assume they would stay good natured, even if you have the most perfect humans there now. It's far more likely that the EU is creating tools to prevent disruption and manipulate markets. The template will likely be followed e…

Yes I'm sure enforcers are looking to fine Bitcoin.

I'm not making that argument. It's a reflection of how the law is about expanding government power without considering technology.

Re: GDPR: Don't Panic

#205
post #48

This doesn't consider some factors that dictate how strong any company will experience their firehose of GDPR requests to be: - how incentivised people are to make GDPR subject access requests of the company (how angry, confused, hostile curious they are) - how easy it is for them to make requests (entirely manual vs. online service) - wildcard factors (internet flash mobs bent on vengeance against a corporate) There…

> The candidate gets back a formatted dump by email of all sorts of recruitment data, including interview notes, etc.

Interview notes would not have to be turned over to the candidate. They are personal opinion of the interviewer even if they mention the candidate. GDPR protects that data: you may not disclose it because it would violate the rights of the interviewer.

Re: GDPR: Don't Panic

#206

For those of you understandably intimidated by the GDPR regulations themselves, here's a good summary in plain English: https://blog.varonis.com/gdpr-requirements-list-in-plain-eng... The UK's ICO also has a good structured summary: https://ico.org.uk/for-organisations/guide-to-the-general-da... In general I agree with the sentiments in this article. I've probably spent a total of three to four days reading around th…

I am concerned that the effect of this legislation on the private individual is the opposite of the stated intention. People are being forced to sign agreements which jeopardise the natural rights to their data which they would otherwise have. One example: a friend who has a very pretty daughter was asked by her school to give them the right to film her and to use any and all such recordings as they see fit for 50 ye…

Is that a GDPR issue, or a copyright/"release" issue?

(note that privacy and GDPR issues apply differently for children)

> natural rights to their data which they would otherwise have

This is not a thing. Data has traditionally "belonged" to the entity doing the recording of the data.

Re: GDPR: Don't Panic

#207
I've been doing a bit of consulting work on the GDPR and for the most part small sites aren't going to have a lot of headache dealing with the GDPR requirements.

Typical, simplified, workflow (varies):

1) Review what data you collect and why

2) Document these in an updated privacy policy along with third parties you share data with and why

3) Update all forms on your site collecting personal information

4) Update your cookie policy and the way you handle cookies, for some of these you might need consent, for some there might be exemptions

5) If you expect this to be an issue, set up automated means of handling requests pertaining to data subject rights, otherwise process them as they come via email

While some smaller sites are getting around the need for an EU rep by claiming that they are only processing data occasionally and not on a large scale (whatever that means, as it's not defined by the GDPR) there is a big problem with getting an EU rep, because as opposed to a DPO, which doesn't have liability, your EU representative "should be subject to enforcement proceedings in the event of non-compliance by the controller or processor." making that natural or legal person liable, so you won't be able to easily outsource this.

If you have set up shop in the EU, then it's pretty easy to handle the aspect of an EU rep. Also, if you're transferring data between your EU and US offices/datacenters, you can self-certify under the privacy shield, starting from ~$250 per year to not have to deal with binding corporate rules or standard contractual causes, so that you can effectively make these transfers "safe" under the GDPR, along with various technical safeguards, of course.

Re: GDPR: Don't Panic

#208

For those of you understandably intimidated by the GDPR regulations themselves, here's a good summary in plain English: https://blog.varonis.com/gdpr-requirements-list-in-plain-eng... The UK's ICO also has a good structured summary: https://ico.org.uk/for-organisations/guide-to-the-general-da... In general I agree with the sentiments in this article. I've probably spent a total of three to four days reading around th…

> I don't really see what's special about this law The key change is the fairly explicit punishments and apparent intent to hand them out for non-compliance. A lot of older regulations get considered by companies but the issues relegated, officially or otherwise, to "yeah, we'll apologise and fix that when someone notices" which might not be a good way to manage the risk management after next Friday. > ... might feel…

The consulting companies use exactly the same MO that Y2K consultants used. Cherry picking case studies and data sets to make executives think the sky is falling when in reality it's not all that hard to be compliant with GDPR and it really is comprehensible by an average person spending a day or 2 reading up on it.

Re: GDPR: Don't Panic

#209
post #48

This doesn't consider some factors that dictate how strong any company will experience their firehose of GDPR requests to be: - how incentivised people are to make GDPR subject access requests of the company (how angry, confused, hostile curious they are) - how easy it is for them to make requests (entirely manual vs. online service) - wildcard factors (internet flash mobs bent on vengeance against a corporate) There…

> The candidate gets back a formatted dump by email of all sorts of recruitment data, including interview notes, etc. Interview notes would not have to be turned over to the candidate. They are personal opinion of the interviewer even if they mention the candidate. GDPR protects that data: you may not disclose it because it would violate the rights of the interviewer.

Do you have a citation for that?

Re: GDPR: Don't Panic

#210

The GDPR gets so much hate because it hits so many businesses where it hurts: data. GDPR "simply" gives you guidelines on how you can handle data from people within the EU. And that that data cannot be handled so liberally as it has been before. Of course that's annoying from a business perspective, but from an individuals privacy perspective, it's fantastic.

I think it gets "hate" from people who don't have much data but they still have to implement all the requirements, which go beyond than their own data storage. Ad-supported websites are probably the most common case here, even if the sites don't store any data themselves.
Post reply on HN