Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

241–250 of 833 posts

Re: GDPR: Don't Panic

#241
post #107

There's no hysteria. There's just FUD disinformation campaign - businesses who make a lot of money thanks to privacy violations are very unhappy with this and they have a lot of voices.

I'm unhappy with this because now I have to do a lot of extra work verifying that I'm not breaking some law, then implement changes in both code and license agreements, then get all the users to agree.

I've had zero profit from user data so far - to the contrary. If everyone could be billed just with some cryptocurrency, totally anonymous, that would be great.

Re: GDPR: Don't Panic

#243
post #185

Earlier quoted context omitted.

What ? It's the opposite, it allow you to access and delete the data, even if you gave consent one time. And your image concern a lot of other old laws, even if you sell it you can get it back later.

I have difficulty in understanding your language and in following your logic. Surely, signing away the rights to your records for over 50 years can not be better for you than not signing them?

I'm skeptical this is genuinely because of GDPR.

Consent could be withdrawn before or after GDPR. My guess is that the school have realised they're at risk of having to reprint all their promotional materials if consent is withdrawn.

So they need a contract, a model release. They needed that before GDPR. If you don't like the terms, don't sign it.

Re: GDPR: Don't Panic

#244

The GDPR gets so much hate because it hits so many businesses where it hurts: data. GDPR "simply" gives you guidelines on how you can handle data from people within the EU. And that that data cannot be handled so liberally as it has been before. Of course that's annoying from a business perspective, but from an individuals privacy perspective, it's fantastic.

I think it gets "hate" from people who don't have much data but they still have to implement all the requirements, which go beyond than their own data storage. Ad-supported websites are probably the most common case here, even if the sites don't store any data themselves.

And that is a good thing. This >23 different trackers and adservers just to read crappy news content BS is so nice to be shaken.

I really love the GDPR for just making the life for such business models way harder.

Implementing data, analytics, tracking and stuff in a way that is compliant with GDPR (or its local equivalents) is doable and from an architectural point of view even interesting imho.

I love building GDPR conforming data architectures with my clients right now.

Re: GDPR: Don't Panic

#245

Earlier quoted context omitted.

How he thinks this house of bureaucrats will be able to judge that John Does complaint has any merit? The same way judges can throw out a case without going to trial. Checking if the complaint makes sense, if it represents an actual violation as described, etc. Anyone dealing with the public knows that a huge chunk of the complaints don't even pass that bar.

John Doe says company has personal information on him and doesn't want to delete it. Shows email exchange with the company and company is stating they don't have his personal data, so there is nothing to delete. How do they judge the case has a merit? Let's say a group forms on xchan type of site and flood company and "clearing house" with such claims.

Unless Doe can provide any actual reason for believing they have his data, and as long as the data handling process of the company is sound, the regulator will just close the issue. At least that's my experience.

Remember that the Data Protection Directive, which already allows citizens to ask companies if they have data on them and to correct incorrect data, has been around from 1995, yet there hasn't been any mobs ruining companies.

Re: GDPR: Don't Panic

#246

For those of you understandably intimidated by the GDPR regulations themselves, here's a good summary in plain English: https://blog.varonis.com/gdpr-requirements-list-in-plain-eng... The UK's ICO also has a good structured summary: https://ico.org.uk/for-organisations/guide-to-the-general-da... In general I agree with the sentiments in this article. I've probably spent a total of three to four days reading around th…

I am concerned that the effect of this legislation on the private individual is the opposite of the stated intention. People are being forced to sign agreements which jeopardise the natural rights to their data which they would otherwise have. One example: a friend who has a very pretty daughter was asked by her school to give them the right to film her and to use any and all such recordings as they see fit for 50 ye…

The only thing which would make that outrageous would be an element of force (which would make it not consent anyway, but I digress). Instead, you're giving an example that explicitly allows for a denial. That's exactly as it always should have been, so I really don't understand what the point is that you're trying to make here.

Re: GDPR: Don't Panic

#247
post #206

Earlier quoted context omitted.

Is that a GDPR issue, or a copyright/"release" issue? (note that privacy and GDPR issues apply differently for children) > natural rights to their data which they would otherwise have This is not a thing. Data has traditionally "belonged" to the entity doing the recording of the data.

Well, I don't know. I am asking. She is a minor under orders of the school, so she is in no position to refuse being filmed, anywhere in the school, showers, toilets, anything. Suppose she in later life becomes a Hollywood star and her school starts selling these recordings of her on the internet because, after all, her father has given them a permission to do this for fifty years ahead?

"she is in no position to refuse being filmed, anywhere in the school, showers, toilets, anything."

This actually made me chuckle a little. I genuinely have no idea if you're joking here because this sentence is ridiculous.

Re: GDPR: Don't Panic

#248

Earlier quoted context omitted.

I think it gets "hate" from people who don't have much data but they still have to implement all the requirements, which go beyond than their own data storage. Ad-supported websites are probably the most common case here, even if the sites don't store any data themselves.

And that is a good thing. This >23 different trackers and adservers just to read crappy news content BS is so nice to be shaken. I really love the GDPR for just making the life for such business models way harder. Implementing data, analytics, tracking and stuff in a way that is compliant with GDPR (or its local equivalents) is doable and from an architectural point of view even interesting imho. I love building GDPR…

i suggest you remove the 3 trackers from your blog, or at least let me see it without them. I m not trying to be snarky, just pointing out that removing everything is often very hard.

Re: GDPR: Don't Panic

#249
post #145

Earlier quoted context omitted.

Maximum possible fine for repeated worst possible violation after ignoring previous attempts at regulation and not making changes after previous smaller fines. It's not a minimum.

It takes time, and real money to be compliant, and getting slow on this quite plausibly can make one a repeat offender. You can, of course, say "don't be slow then", however, when for an out-of-EU entity (be it biz, or NGO) simple math doesn't show it is worth the effort, then it makes perfect sense to stop offering services to EU. Which is a side effect of the legislation. OP apparently understands it puts GDPR in a…

But merely being a repeat offender isn't enough to trigger the maximum fine.

You'd have to be a consistant repeat offender, with no effort made at remediation, with no cooperation with the regulator, and probably handling sensitive or financial data.

Here's a list of recent actions taken. I think the current maximum fine is £500,000. Have a look through a few of these hopefully it's somewhat reassuring.

https://ico.org.uk/action-weve-taken/enforcement/

Re: GDPR: Don't Panic

#250

For those of you understandably intimidated by the GDPR regulations themselves, here's a good summary in plain English: https://blog.varonis.com/gdpr-requirements-list-in-plain-eng... The UK's ICO also has a good structured summary: https://ico.org.uk/for-organisations/guide-to-the-general-da... In general I agree with the sentiments in this article. I've probably spent a total of three to four days reading around th…

The amount of discretion and lack of clarity in the penalties is part of the problem. It opens you up to risk based on the whims of politics and the regulators and increases uncertainty. Laws should be clear, limited, and understandable - this is not.

I really don't know why people think that the authorities will (or even could) automatically punish each minor infraction with 4 % of global revenue or 20 million €. GPDR article 87 specifies in great detail when fines should be imposed and how their value should be calculated, and the Article 29 WP also has a guideline on that:

https://ec.europa.eu/newsroom/just/document.cfm?doc_id=47889

It is therefore simply not possible for a data protection authority to impose arbitrary or ridiculously high fines as they would never hold up in court.

Post reply on HN