Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

211–220 of 833 posts

Re: GDPR: Don't Panic

#211
post #60

I was hoping for a nice respite to the anti-GDPR stuff we've seen recently, but this is just naked propaganda. In particular, the sentence: "the GDPR has the potential to escalate to those levels but in the spirit of the good natured enforcers ..." The author seems to have the idea that bureaucratic EU systems are inherently "good" and that even if things look bad on paper, it will be fine because they are "good" peo…

I think this is a very distinct difference between the EU with the scaremongering removed, and e.g. the US: My experience of the EU has been that they've consistently looked out for my interests. Even in the face of the local government (I live in the UK) that have kept fighting for positions I find abhorrent (e.g. UK governments keep complaining about having to abide by EU human rights regulations for example). Yes,…

Not sure id 100% agree and they are at the mercy of individual governments who have in some cases gone against the spirt of some of the eu regs for example Spain's implementation of TUPE.

Re: GDPR: Don't Panic

#212
> If becoming compliant with the law will cause your business to go under that is more or less the same as saying that your business is built on gross privacy violations. So if that’s your business model then good riddance to you and your company.

Hear hear!

Re: GDPR: Don't Panic

#213

One question that I have thought about is how are foreigners supposed to learn about the GDPR's existence? If it wasn't for the fact that I spend more time on HN that I should I would never have heard of it. I doubt there are many businesses here in Australia that know about it.

I first learned about it when I did a google search to figure out why I was getting so many “we’ve changed our privacy policy” emails.

Re: GDPR: Don't Panic

#214

Earlier quoted context omitted.

> you also need a privacy policy if you are receiving phone calls. did you know that? You mean your website needs to have a note next to your phone number saying something like "we will not record your phone calls", and if there isn't, you're liable to be fined?

that or a mention directly at the start of the conversation.

Which they all do "this call may be monitored for training purposes"

Re: GDPR: Don't Panic

#215

There's certainly no need to panic. The article doesn't address that apart from mindless hysteria there are some very real issues with GDPR. It doesn't have to of course because as the title suggests it's more about dispelling panic than about giving concrete advice. However, many real-life problems seemingly haven't even been considered by legislative bodies. In GDPR support forums questions like these have been rou…

1) Respond to requests about removal of personal data, do not sell data, inform about data leaks and handle them, if outsourcing, check compliance. 2) Any item that is not legal there will be just void in court. You cannot be sued about an invalid legal policy, but only after breaking the law. The policies do not subsume law. About the only thing you need to publish is which data is collected, how it is processed (an…

1.) That "if outsourcing, check compliance" part isn't trivial, though. Some suppliers still don't provide data processing agreements. For example, as of now it seems like I won't be able to use DocuSign for digitally signing contracts anymore because they seem to not understand what the new laws implies for them and consequently don't provide a DPA. The last time I checked competitors didn't do so either. It's good that companies have to check their processes for privacy compliance but if that disrupts a company's operations with no real remedy other than falling back to paper-based processes that's definitely a problem (admittedly in this case not one that could be solved by legislative bodies)

3.) No, unfortunately it isn't that easy. Some people - lawyers even - argue that merely someone contacting you via email or handing you a business card doesn't necessarily constitute legitimate interest on your part to process their contact data for the purpose of contacting them in the future. I disagree with that opinion but that people are even arguing about this shows that this isn't just business as usual.

5.) You could argue that this has the potential for breaking how the web has worked until now. If you now have to check for legal compliance first each time before merely linking to an external resource (because that might reveal the user's IP address) that simply doesn't scale. Linking to and drawing upon external resources arguably is what makes the web the web.

Re: GDPR: Don't Panic

#216
post #185

Earlier quoted context omitted.

I am concerned that the effect of this legislation on the private individual is the opposite of the stated intention. People are being forced to sign agreements which jeopardise the natural rights to their data which they would otherwise have. One example: a friend who has a very pretty daughter was asked by her school to give them the right to film her and to use any and all such recordings as they see fit for 50 ye…

What ? It's the opposite, it allow you to access and delete the data, even if you gave consent one time. And your image concern a lot of other old laws, even if you sell it you can get it back later.

I have difficulty in understanding your language and in following your logic. Surely, signing away the rights to your records for over 50 years can not be better for you than not signing them?

Re: GDPR: Don't Panic

#217
post #163

https://pawelurbanek.com/gdpr-compliance-blog-rails My take on GDPR compliance from a solo developer perspective without a legal team to back him up.

> IP addresses collected by Google Analytics

Why should this be your headache? It's collected by Google, not you.

Re: GDPR: Don't Panic

#219
Remember guys, while you are stressing over how to work with GDPR, Facebook literally listed all their existing data collection items and forced everyone to consent. Total increase in privacy: 0

Re: GDPR: Don't Panic

#220
post #59

I can't help but love the turmoil GDPR is causing in the adtech "industry". Like wasps buzzing around the exterminator who's about to destroy their nest.

When people losing their jobs due to government overreach makes you happy, check your motivations.
Post reply on HN