Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

251–260 of 833 posts

Re: GDPR: Don't Panic

#251
> The GDPR will require me to hire people and my entity is too small to be able to afford this

Q: Does my business need to appoint a Data Protection Officer (DPO)?

A: DPOs must be appointed in the case of: (a) public authorities, (b) organizations that engage in large scale systematic monitoring, or (c) organizations that engage in large scale processing of sensitive personal data (Art. 37). If your organization doesn’t fall into one of these categories, then you do not need to appoint a DPO.

source: https://www.eugdpr.org/gdpr-faqs.html

Re: GDPR: Don't Panic

#252
post #199

> I was actually surprised by how easy it is to read it there's a whole two hundred post debate around here whether ip are or aren't pii on their own, with the wast majority holding the wrong position. there's a whole branch of gdpr that people aren't considering, which is not related to software but to your business (i.e. your mail calendar). you also need a privacy policy if you are receiving phone calls. did you k…

No, people were correctly answering the specific question: is an IP address on its own personal data? (No, it can't be used to identify a natural person). THe problem is that it's a stupid question. No-one has just IP addresses, they have a mix of data. If you can combine the IP address with anything else to identify a natural person it becomes personal data.

And you’re wrong

Ip are personal data https://ec.europa.eu/info/law/law-topic/data-protection/refo...

Without conditions. Even hashing them doesn’t make them ‘irreversibly anonimized’ because the ip space is too small for hashing to be irreversible. A rainbow table can be built with all ips and use to deanonimize the ip.

Re: GDPR: Don't Panic

#253
post #206

Earlier quoted context omitted.

Is that a GDPR issue, or a copyright/"release" issue? (note that privacy and GDPR issues apply differently for children) > natural rights to their data which they would otherwise have This is not a thing. Data has traditionally "belonged" to the entity doing the recording of the data.

Well, I don't know. I am asking. She is a minor under orders of the school, so she is in no position to refuse being filmed, anywhere in the school, showers, toilets, anything. Suppose she in later life becomes a Hollywood star and her school starts selling these recordings of her on the internet because, after all, her father has given them a permission to do this for fifty years ahead?

You could just ... not sign the permission form?

(Which EU country is this btw?)

Re: GDPR: Don't Panic

#254
post #130

Earlier quoted context omitted.

> CNIL then immediately changed their mind and dished out a fine So, there's no opportunity for litigating using their previous statements? At least now I understand why you're on every GDPR thread.

Hah, no. I guess you haven't dealt much with regulators in the past. Regulators can never be held to anything they say. When you ask questions, if they answer at all, it always comes with a disclaimer that it's merely "guidance" and not binding. If they later change their mind, it's always a "clarification" and not a change. The sort of people who think vague regulations are a good idea are the sort of people who thi…

The EU HASN'T delegated everything to local regulators. Have you not come across the Article 29 Working Party, which is dedicated to standardising GDPR interpretations across the EU?

Re: GDPR: Don't Panic

#255
post #209

Earlier quoted context omitted.

> The candidate gets back a formatted dump by email of all sorts of recruitment data, including interview notes, etc. Interview notes would not have to be turned over to the candidate. They are personal opinion of the interviewer even if they mention the candidate. GDPR protects that data: you may not disclose it because it would violate the rights of the interviewer.

Do you have a citation for that?

Read the actual law (it's in english, so you can). It mentions this fairly unambiguously.

Re: GDPR: Don't Panic

#256
post #251

> The GDPR will require me to hire people and my entity is too small to be able to afford this Q: Does my business need to appoint a Data Protection Officer (DPO)? A: DPOs must be appointed in the case of: (a) public authorities, (b) organizations that engage in large scale systematic monitoring, or (c) organizations that engage in large scale processing of sensitive personal data (Art. 37). If your organization does…

There is a legitimate question here, where does "large scale" begin? There are a lot of similar questions that nobody can personally guarantee they know the answers for.

Re: GDPR: Don't Panic

#257

Earlier quoted context omitted.

The amount of discretion and lack of clarity in the penalties is part of the problem. It opens you up to risk based on the whims of politics and the regulators and increases uncertainty. Laws should be clear, limited, and understandable - this is not.

I really don't know why people think that the authorities will (or even could) automatically punish each minor infraction with 4 % of global revenue or 20 million €. GPDR article 87 specifies in great detail when fines should be imposed and how their value should be calculated, and the Article 29 WP also has a guideline on that: https://ec.europa.eu/newsroom/just/document.cfm?doc_id=47889 It is therefore simply not p…

I'm starting to wonder if there's an active disinformation campaign about this somewhere. Are people getting their fears from Facebook again?

Edit: If there is such a thing I bet it's Cambridge Analytica/"SCL group" involved, since they made their money from large scale nonconsensual abuse of political personal data, and have an arm dedicated to swinging elections with misleading Facebook adverts.

Re: GDPR: Don't Panic

#258

The GDPR gets so much hate because it hits so many businesses where it hurts: data. GDPR "simply" gives you guidelines on how you can handle data from people within the EU. And that that data cannot be handled so liberally as it has been before. Of course that's annoying from a business perspective, but from an individuals privacy perspective, it's fantastic.

I think it gets "hate" from people who don't have much data but they still have to implement all the requirements, which go beyond than their own data storage. Ad-supported websites are probably the most common case here, even if the sites don't store any data themselves.

Or perhaps these people/businesses have much more data about you and don't want to share how they monetize their "free" services by selling/renting/aggregating/analyzing your data?

Think of all the free apps: I was in a conference with startup founders bragging about the business they make selling the location data of app users by incorporating some third party libraries in their apps without the users knowing. Of course, everything is anonymized, is it?

Add-supported websites on the other hand have only to document what is going on and get the consent of the user. That's a simple notification bar with a button, like the cookie notice, plus a page detailing the privacy policy. The GDPR even mentions legitime reasons for collecting, storing and transmitting personal identifiable data like technical or business needs. And in addition, almost all ad networks are going to anonymize IP addresses by stripping some bits and have opt-out features for being profiled.

Re: GDPR: Don't Panic

#259
post #120

Earlier quoted context omitted.

It is highly unlikely that a lot of requests will "sink" your company. As per the GDPR, you have a month to respond to requests and you can extend this period by two more months by telling the user that you need more time to process their request. (See article 12 for reference)

If 10% of the members of my website request a GDPR, then my website will no longer exist. The processing time for that would be a decade.

Then automate it. If you can't automate it within one month plus two months extension, you have bigger problems than GDPR requests.

Re: GDPR: Don't Panic

#260
Do what I say do not do what I do.

Today I've been asked by a library of "Junta de Anadalucia - Spain" to accept it's terms and conditions to use the wifi internet connection provided for it's users and it's a clear violation of the GDPR by a government body, basically they're asking for a blank check to do whatever they want without boring to ask/inform the user.

Translation by translate.google:

====

The Telecommunications Corporate Network of the Junta de Andalucía reserves the right to monitor and collect information while the user is connected to the Service. This information can be used at the discretion of the Telecommunications Corporate Network of the Junta de Andalucía and can even be shared with the State Security Bodies, their associates or suppliers.

Likewise, the Telecommunications Corporate Network of the Junta de Andalucía reserves the right to revise this agreement at any time.

The user must accept the General Conditions of Access each time they use the service and, it is your responsibility to review it each time the Service is accessed in case there has been any change.

The Telecommunications Corporate Network of the Junta de Andalucía, reserves the right to withdraw the Service, modify the specifications or forms of use thereof, as well as change access codes, users, passwords and other security elements necessary to access the Service . IF YOU DO NOT AGREE TO THESE TERMS, INCLUDING ANY MODIFICATIONS, DO NOT ACCESS OR USE THIS SERVICE.

====

Post reply on HN