Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

281–290 of 833 posts

Re: GDPR: Don't Panic

#281
post #145

Earlier quoted context omitted.

Well, lots of ends open to interpretation, and $20 mln fine - so obviously nothing to care about! Hysteria!

Maximum possible fine for repeated worst possible violation after ignoring previous attempts at regulation and not making changes after previous smaller fines. It's not a minimum.

>Maximum possible fine for repeated worst possible violation after ignoring previous attempts at regulation and not making changes after previous smaller fines.

Nothing in the GDPR states this. It's obviously the intent, but ultimately it's left up to the bon vouloir of EU regulators.

It is perfectly legal under the GDPR to make an example out of you by levying the maximum fine for a first offense, and without warning.

Re: GDPR: Don't Panic

#282
This article actually points out my philosophical problem with GDPR. In one point he says you have to be compliant if you want to do business in the EU. In another he observed that it is difficult (maybe impossible) to block EU folks from coming to a web presence. It’s the expansive reach that bugs me.

I’ll note that for real businesses this is just a thought excercise, but it’s one I keep coming back to. What if some less reasonable entity attempted to regulate in this way?

Re: GDPR: Don't Panic

#283

Earlier quoted context omitted.

The amount of discretion and lack of clarity in the penalties is part of the problem. It opens you up to risk based on the whims of politics and the regulators and increases uncertainty. Laws should be clear, limited, and understandable - this is not.

The law says that the fines should be "effective, proportionate and dissuasive". That gives companies ample room to challenge a fine that is way out of proportion to the damages caused to their users.

You say this as though "challenging a fine" were trivial.

After countless months spent in a courtroom and tens of thousands of Euros in legal fees, even if you win, you lose.

Re: GDPR: Don't Panic

#284

Do what I say do not do what I do. Today I've been asked by a library of "Junta de Anadalucia - Spain" to accept it's terms and conditions to use the wifi internet connection provided for it's users and it's a clear violation of the GDPR by a government body, basically they're asking for a blank check to do whatever they want without boring to ask/inform the user. Translation by translate.google: ==== The Telecommuni…

Well, presumably you can report them to the relevant regulator, then. That's the point of the law.

Re: GDPR: Don't Panic

#285

Earlier quoted context omitted.

I think this is a common misinterpretation though because of the lanauge - that the maximum fine is actually the minimum, because the figures that are talked about are "€20m or 4% of global turnover, whichever is the greatest." It's the emphasis on "the greatest" that has an undercurrent of "we're going to fine you the maximum of these two numbers."

I'm not sure what you mean by "actually the minimum". They will find you the maximum of those two numbers, at most, if you flagrantly disregard the law.

Yeah, this is the confusion - it's difficult to write it out in a way that isn't ambiguous! I think the fact that there are two numbers, the higher of which is the maximum fine, may imply to some people that the lower figure is the minimum - i.e. if 4% of your global turnover is €100m then €20m is the minimum - but of course there in fact isn't a minimum. It might have helped comprehension if there had been an arbitrary minimum figure - say €100 - to anchor the discussions.

Re: GDPR: Don't Panic

#286

There's certainly no need to panic. The article doesn't address that apart from mindless hysteria there are some very real issues with GDPR. It doesn't have to of course because as the title suggests it's more about dispelling panic than about giving concrete advice. However, many real-life problems seemingly haven't even been considered by legislative bodies. In GDPR support forums questions like these have been rou…

I think this lack of implementation clarity is definitely a problem, as it is with CE marking; the legislation sets out "principles", but there's a lot of interpretation that has to be done between those and specific real details.

Re: GDPR: Don't Panic

#287
post #107

There's no hysteria. There's just FUD disinformation campaign - businesses who make a lot of money thanks to privacy violations are very unhappy with this and they have a lot of voices.

I'm unhappy with this because now I have to do a lot of extra work verifying that I'm not breaking some law, then implement changes in both code and license agreements, then get all the users to agree. I've had zero profit from user data so far - to the contrary. If everyone could be billed just with some cryptocurrency, totally anonymous, that would be great .

The only thing I can do as a customer is be mildly amused at the fact that you're complaining it's inconvenient for you to respect my privacy now that a law is coming into effect forcing you to do so.

From the other end of the spectrum, I know you're wildly exaggerating the difficulty of compliance.

Re: GDPR: Don't Panic

#288
post #249

Earlier quoted context omitted.

It takes time, and real money to be compliant, and getting slow on this quite plausibly can make one a repeat offender. You can, of course, say "don't be slow then", however, when for an out-of-EU entity (be it biz, or NGO) simple math doesn't show it is worth the effort, then it makes perfect sense to stop offering services to EU. Which is a side effect of the legislation. OP apparently understands it puts GDPR in a…

But merely being a repeat offender isn't enough to trigger the maximum fine. You'd have to be a consistant repeat offender, with no effort made at remediation, with no cooperation with the regulator, and probably handling sensitive or financial data. Here's a list of recent actions taken. I think the current maximum fine is £500,000. Have a look through a few of these hopefully it's somewhat reassuring. https://ico.o…

Note that this is the UK agency, you might see different behaviors if you scanned the Belgian regulators enforcement list.

Re: GDPR: Don't Panic

#289

The GDPR gets so much hate because it hits so many businesses where it hurts: data. GDPR "simply" gives you guidelines on how you can handle data from people within the EU. And that that data cannot be handled so liberally as it has been before. Of course that's annoying from a business perspective, but from an individuals privacy perspective, it's fantastic.

I don't think that's fair.

I rather think it gets a lot of hate because it leaves a lot to the discretion of the regulators. Overall, the SMEs I talk to don't have a problem with regulating data (most think it will pop the gangrenous ad-tech bubble). It's the lack of predictability that bothers them.

Re: GDPR: Don't Panic

#290
post #124
post #48

This doesn't consider some factors that dictate how strong any company will experience their firehose of GDPR requests to be: - how incentivised people are to make GDPR subject access requests of the company (how angry, confused, hostile curious they are) - how easy it is for them to make requests (entirely manual vs. online service) - wildcard factors (internet flash mobs bent on vengeance against a corporate) There…

You can do this already with the existing Data Protection Act. Businesses have not drowned in subject access requests. People seem to forget that data protection isn't new , it's just being beefed up a bit. https://ico.org.uk/for-organisations/guide-to-data-protectio... Another link from 2012 describing how to handle data protection in the 1998 framework: http://www.shoosmiths.co.uk/client-resources/legal-updates/D..…

See "Europe vs Facebook" for another pre-GDPR example where people were obtaining data Facebook stored on them via existing data protection laws: http://www.europe-v-facebook.org/EN/en.html
Post reply on HN