Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

231–240 of 833 posts

Re: GDPR: Don't Panic

#231
post #185

Earlier quoted context omitted.

What ? It's the opposite, it allow you to access and delete the data, even if you gave consent one time. And your image concern a lot of other old laws, even if you sell it you can get it back later.

I have difficulty in understanding your language and in following your logic. Surely, signing away the rights to your records for over 50 years can not be better for you than not signing them?

This law has nothing to do with signing away the rights of your image to be used for publicity, though. GDPR does not come into play at all in the scenario with your friend’s daughter; the school is likely abusing laws in their request and should be investigated, but those laws aren’t related to GDPR and the existence of GDPR does not somehow cause the daughter’s position to be weaker here.

Re: GDPR: Don't Panic

#232

For those of you understandably intimidated by the GDPR regulations themselves, here's a good summary in plain English: https://blog.varonis.com/gdpr-requirements-list-in-plain-eng... The UK's ICO also has a good structured summary: https://ico.org.uk/for-organisations/guide-to-the-general-da... In general I agree with the sentiments in this article. I've probably spent a total of three to four days reading around th…

Reminder: you have to legally comply with every letter of the GDPR, not just the TLDR version. Saying "but we implemented the TLDR version" is not a legal defence.

Saying "we got the major stuff right, missed some of the details, sorry about that" will keep the fine small. And... de minimis non curat lex.

Re: GDPR: Don't Panic

#233
post #163

https://pawelurbanek.com/gdpr-compliance-blog-rails My take on GDPR compliance from a solo developer perspective without a legal team to back him up.

> IP addresses collected by Google Analytics Why should this be your headache? It's collected by Google, not you.

I am afraid it is not so simple. There is a thing with data collector, and data controller in GDPR I don't full understand yet. It's not like you're not responsible for data collected by services that you hook up to your application.

Re: GDPR: Don't Panic

#234
post #189

Earlier quoted context omitted.

Run your small company website without gathering personal data? No-one can sue you now, that couldn't before. I'm baffled that so many people believe this. I could complain about you to my country's regulation body. Then they could decide to audit you, and for a first offense issue a warning. If you need the address data for marketing only, and you didn't get an explicit (opt-in) yes to receive marketing, then sorry.…

> No-one can sue you now, that couldn't before. That is not true, GDPR is a law, and in the past most EU countries did not have such stringent requirements. You couldn't be sued (Edit: i mean by the DPA).

My point is that you won't be sued for the GDPR. What might happen is that a complaint is raised with the regulatory body. This is not the same thing as being sued.

Re: GDPR: Don't Panic

#235
post #160

> this particular one has the interesting side effect of causing mass hysteria in the otherwise rational tech sector. * Y2K * Dot Com hysteria * Dot Com crash hysteria * AWS outages * Will robots replace us ? * Will Microsoft crush me ? * Will Google crush me ? * I just raised £30M series A, where my Aeron at * Nosql means I can throw away everything I knew about databases * Web first * Mobile first * XML everywhere…

I chuckled at that sentence as well. It's not that the tech sector is rational, it's that a lot of the people working in it are desperate to maintain a self-image of being a rational, scientific-minded person. Then, if some evidence collides with that self-image, we just blame it on management. Problem solved!

Re: GDPR: Don't Panic

#236
post #185

Earlier quoted context omitted.

What ? It's the opposite, it allow you to access and delete the data, even if you gave consent one time. And your image concern a lot of other old laws, even if you sell it you can get it back later.

I have difficulty in understanding your language and in following your logic. Surely, signing away the rights to your records for over 50 years can not be better for you than not signing them?

GDPR states, that even if you give consent now you can withdraw this consent anytime. So even if OP consents now and in one year decides he/she doesn't want the daughter's videos being used anymore he/she can do this and the school needs to honor that (or else: big fines).

So GDPR helps you in maintaining control over your data as you see fit.

Re: GDPR: Don't Panic

#237
post #208

Earlier quoted context omitted.

> I don't really see what's special about this law The key change is the fairly explicit punishments and apparent intent to hand them out for non-compliance. A lot of older regulations get considered by companies but the issues relegated, officially or otherwise, to "yeah, we'll apologise and fix that when someone notices" which might not be a good way to manage the risk management after next Friday. > ... might feel…

The consulting companies use exactly the same MO that Y2K consultants used. Cherry picking case studies and data sets to make executives think the sky is falling when in reality it's not all that hard to be compliant with GDPR and it really is comprehensible by an average person spending a day or 2 reading up on it.

Exactly that. Working as a data analyst for my agency's clients I had more work in making sure my clients do not panic after having other consultants claiming, that the world will end and what not.

It is possible to comply with GDPR in most cases with not too much of an effort (I know some processual stuff is just boring and ugly, but doable).

It is possible to not have a cookie wall of horror, if you "just" want to do tracking (analytics) or first party onsite marketing.

It will get more complicated with personalized recommendations, profiling and stuff. I have to admit this - especially with third party vendors and such - will be a little bit more fun/challenging.

Re: GDPR: Don't Panic

#238
post #145

Earlier quoted context omitted.

Maximum possible fine for repeated worst possible violation after ignoring previous attempts at regulation and not making changes after previous smaller fines. It's not a minimum.

I think this is a common misinterpretation though because of the lanauge - that the maximum fine is actually the minimum, because the figures that are talked about are "€20m or 4% of global turnover, whichever is the greatest." It's the emphasis on "the greatest" that has an undercurrent of "we're going to fine you the maximum of these two numbers."

I'm not sure what you mean by "actually the minimum". They will find you the maximum of those two numbers, at most, if you flagrantly disregard the law.

Re: GDPR: Don't Panic

#239

>Every company and every project or hobby ever has to be compliant with the law. wrong. if everyone always followed the laws, earth would still be considered flat (at least until more recently).

> and every project or hobby ever

But, in particular, that's wrong because personal projects are exempt.

Re: GDPR: Don't Panic

#240
post #200

Earlier quoted context omitted.

That's not how it works. They don't send a guy to look at your databases.

So how do they know if the response with the data a user requests, are all we've got about them, and if indeed where stored the proper way?

As far as I know, you pay for an audit yourself, and then you send them the results.
Post reply on HN