Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

221–230 of 833 posts

Re: GDPR: Don't Panic

#221
post #189

There's certainly no need to panic. The article doesn't address that apart from mindless hysteria there are some very real issues with GDPR. It doesn't have to of course because as the title suggests it's more about dispelling panic than about giving concrete advice. However, many real-life problems seemingly haven't even been considered by legislative bodies. In GDPR support forums questions like these have been rou…

Run your small company website without gathering personal data? No-one can sue you now, that couldn't before. I'm baffled that so many people believe this. I could complain about you to my country's regulation body. Then they could decide to audit you, and for a first offense issue a warning. If you need the address data for marketing only, and you didn't get an explicit (opt-in) yes to receive marketing, then sorry.…

> No-one can sue you now, that couldn't before.

That is not true, GDPR is a law, and in the past most EU countries did not have such stringent requirements. You couldn't be sued (Edit: i mean by the DPA).

Re: GDPR: Don't Panic

#222
post #48

This doesn't consider some factors that dictate how strong any company will experience their firehose of GDPR requests to be: - how incentivised people are to make GDPR subject access requests of the company (how angry, confused, hostile curious they are) - how easy it is for them to make requests (entirely manual vs. online service) - wildcard factors (internet flash mobs bent on vengeance against a corporate) There…

I agree, and there seems to be a lack of conversation around this! Next week could be ground-zero for all sorts of unintended consequences. Especially, a flashmob of GDPR requests could sink a company.

Enabling people to force a company into bankruptcy using the GDPR is not the intention.

From https://gdpr-info.eu/art-12-gdpr/:

"Where requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive character, the controller may either: "

The quoted bit is about one person, not multiple so not directly applicable. I assume if someone organizes a coordinated flood of requests from multiple persons you can still argue that it is excessive.

I agree that the amount of requests is very uncertain. Within my company I'm planning to make one request (data regarding me as an employee). This to see if they're prepared.

Re: GDPR: Don't Panic

#223

Earlier quoted context omitted.

In an ideal world, yes. But that leads you down a Kafkaesque hole of bureaucracy - at some point you have to stop adding detail and leave things open to interpretation. There are plenty of laws out there with fines "up to €X" and, from my limited experience, I don't think the GDPR is especially ambiguous compared to others.

Well, lots of ends open to interpretation, and $20 mln fine - so obviously nothing to care about! Hysteria!

General law applies as well. There's lots of case law on the size of fines.

Which means in practice that if x other people have been fined around y for an offense similar to yours, your fine has to be in the vicinity of y. Ditto if x people have been fined more for larger offenses or less for smaller. This kind of assessment is routine. General. It's not something that needs to be written into each and every law.

Re: GDPR: Don't Panic

#224
My (EU) clients fall into two camps. Those who haven't had to do a single thing to be GDPR compliant because they were already following the various data protection and privacy laws, and the ones panicking.

The latter group say things like "this is ridiculous, they're making us change so much" but never have an answer to the fact that they're already violating PECR or the Data Protection Act.

Re: GDPR: Don't Panic

#225

For those of you understandably intimidated by the GDPR regulations themselves, here's a good summary in plain English: https://blog.varonis.com/gdpr-requirements-list-in-plain-eng... The UK's ICO also has a good structured summary: https://ico.org.uk/for-organisations/guide-to-the-general-da... In general I agree with the sentiments in this article. I've probably spent a total of three to four days reading around th…

Reminder: you have to legally comply with every letter of the GDPR, not just the TLDR version. Saying "but we implemented the TLDR version" is not a legal defence.

This concern applies to all laws though. Not murdering people doesn't require you to spend ages examining the exact text of a statutory definition of murder. The tl;dr version is enough for me to grasp that kicking somebody in the head until they stop breathing isn't allowed.

Re: GDPR: Don't Panic

#226

Earlier quoted context omitted.

In an ideal world, yes. But that leads you down a Kafkaesque hole of bureaucracy - at some point you have to stop adding detail and leave things open to interpretation. There are plenty of laws out there with fines "up to €X" and, from my limited experience, I don't think the GDPR is especially ambiguous compared to others.

Well, lots of ends open to interpretation, and $20 mln fine - so obviously nothing to care about! Hysteria!

Also, minimal level of $10 mln doesn't look nicer unless you are a big corpo.

Re: GDPR: Don't Panic

#227

For those of you understandably intimidated by the GDPR regulations themselves, here's a good summary in plain English: https://blog.varonis.com/gdpr-requirements-list-in-plain-eng... The UK's ICO also has a good structured summary: https://ico.org.uk/for-organisations/guide-to-the-general-da... In general I agree with the sentiments in this article. I've probably spent a total of three to four days reading around th…

I am concerned that the effect of this legislation on the private individual is the opposite of the stated intention. People are being forced to sign agreements which jeopardise the natural rights to their data which they would otherwise have. One example: a friend who has a very pretty daughter was asked by her school to give them the right to film her and to use any and all such recordings as they see fit for 50 ye…

I am not sure where you are, but this is usually standard. You can’t film someone at a place where there’s some expected form of privacy and use that footage publicly.

Talking about GDPR, the fact they had to ask is proof it works. It’s an opt in. Your friend now has the option to say yes if they want to share it, but the default is no.

There are also provisions for withdrawing consent after giving it. The agreement can’t go above that law.

Re: GDPR: Don't Panic

#228
post #206

Earlier quoted context omitted.

I am concerned that the effect of this legislation on the private individual is the opposite of the stated intention. People are being forced to sign agreements which jeopardise the natural rights to their data which they would otherwise have. One example: a friend who has a very pretty daughter was asked by her school to give them the right to film her and to use any and all such recordings as they see fit for 50 ye…

Is that a GDPR issue, or a copyright/"release" issue? (note that privacy and GDPR issues apply differently for children) > natural rights to their data which they would otherwise have This is not a thing. Data has traditionally "belonged" to the entity doing the recording of the data.

Well, I don't know. I am asking. She is a minor under orders of the school, so she is in no position to refuse being filmed, anywhere in the school, showers, toilets, anything.

Suppose she in later life becomes a Hollywood star and her school starts selling these recordings of her on the internet because, after all, her father has given them a permission to do this for fifty years ahead?

Re: GDPR: Don't Panic

#229
post #185

Earlier quoted context omitted.

What ? It's the opposite, it allow you to access and delete the data, even if you gave consent one time. And your image concern a lot of other old laws, even if you sell it you can get it back later.

I have difficulty in understanding your language and in following your logic. Surely, signing away the rights to your records for over 50 years can not be better for you than not signing them?

English may not be my mother tongue but I can logically follow an argument. Your friend' daughter was not obligated to sign such contract and GDPR reinforce previous laws protecting her image ;)

Re: GDPR: Don't Panic

#230

Earlier quoted context omitted.

That's ridiculous. Has anyone in this thread actually ever run a recruiting operation? I have. There's no way we will be deleting interview notes the moment a candidate is rejected. For one, we have to be able to prove later that we didn't reject based on grounds of discrimination (other regulations). But you also need the ability to review what your interviewers are doing to ensure consistency and quality of assessm…

> I have argued above that I legitimately need interview notes for the operation of my business. I agree that you do legitimately need interview notes, but I don't understand why this conflicts with GDPR. In other words, why am I not allowed to see my interview notes?

We were talking above about deleting them, not publishing them.

But interview notes tend to contain personal evaluations of people, often critical. If interviewers believe they are effectively having to criticise people to their face (which is what this change would do), then they won't be willing to be as honest. No interviewer wants an angry job candidate tracking them down via LinkedIn or whatever and then getting mad because you wrote that they sucked in their notes.

This is an interpretation of the GDPR that I don't think makes any sense or aligns with the original intentions at all, but moreover, if it was interpreted and enforced that way it simply means firms would switch to discussing candidates in person and not write down evaluation notes at all.

Post reply on HN