Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

291–300 of 833 posts

Re: GDPR: Don't Panic

#291

For those of you understandably intimidated by the GDPR regulations themselves, here's a good summary in plain English: https://blog.varonis.com/gdpr-requirements-list-in-plain-eng... The UK's ICO also has a good structured summary: https://ico.org.uk/for-organisations/guide-to-the-general-da... In general I agree with the sentiments in this article. I've probably spent a total of three to four days reading around th…

There is nothing - and I do mean nothing - written into the GDPR that requires any warnings of any kind, or places any limits on fines, except for $10/$20 million or 4% of revenue, whichever is greater. Period. A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR. The idea that "yes it says that but we can trust EU regulators to not assess large fines against foreign…

There is actually an over-arching requirement for proportionality in all EU regulation: https://ukhumanrightsblog.com/2015/06/27/supreme-court-on-eu...

Re: GDPR: Don't Panic

#292
post #48

This doesn't consider some factors that dictate how strong any company will experience their firehose of GDPR requests to be: - how incentivised people are to make GDPR subject access requests of the company (how angry, confused, hostile curious they are) - how easy it is for them to make requests (entirely manual vs. online service) - wildcard factors (internet flash mobs bent on vengeance against a corporate) There…

> The candidate gets back a formatted dump by email of all sorts of recruitment data, including interview notes, etc. Interview notes would not have to be turned over to the candidate. They are personal opinion of the interviewer even if they mention the candidate. GDPR protects that data: you may not disclose it because it would violate the rights of the interviewer.

That's not true.

Under the existing Data Protection Directive these notes are subject to people making a Subject Access Request.

Re: GDPR: Don't Panic

#293
post #291

Earlier quoted context omitted.

There is nothing - and I do mean nothing - written into the GDPR that requires any warnings of any kind, or places any limits on fines, except for $10/$20 million or 4% of revenue, whichever is greater. Period. A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR. The idea that "yes it says that but we can trust EU regulators to not assess large fines against foreign…

There is actually an over-arching requirement for proportionality in all EU regulation: https://ukhumanrightsblog.com/2015/06/27/supreme-court-on-eu...

But that is in the eye of the beholder. With a maximum fine of $20 million, a country like Germany might say, for example, "Ok, small American company, yours was a minor violation. We'll only assess a $2 million fine - that's only 10% of the maximum! See how lenient and proportional we are? Danke und tschüss!"

Re: GDPR: Don't Panic

#294

Here in UK I have been receiving about 5-10 emails a day from various companies - most of whom I don't remember - telling me I need to sign up again so they can keep my details and keep spamming me. Fantastic.

[deleted]

Re: GDPR: Don't Panic

#295

Earlier quoted context omitted.

I'm not sure what you mean by "actually the minimum". They will find you the maximum of those two numbers, at most, if you flagrantly disregard the law.

Yeah, this is the confusion - it's difficult to write it out in a way that isn't ambiguous! I think the fact that there are two numbers, the higher of which is the maximum fine, may imply to some people that the lower figure is the minimum - i.e. if 4% of your global turnover is €100m then €20m is the minimum - but of course there in fact isn't a minimum. It might have helped comprehension if there had been an arbitr…

Ah, I see what you mean now. That's not how I understood it, but some people might.

Re: GDPR: Don't Panic

#296

Here in UK I have been receiving about 5-10 emails a day from various companies - most of whom I don't remember - telling me I need to sign up again so they can keep my details and keep spamming me. Fantastic.

I have a lot of companies emailing me saying I can opt-out, I thought that was the opposite of what the law is saying? Eg. If you continue using our service after 23th of May you automatically agree to the new terms. Huh?

Re: GDPR: Don't Panic

#297
post #200

Earlier quoted context omitted.

That's not how it works. They don't send a guy to look at your databases.

So how do they know if the response with the data a user requests, are all we've got about them, and if indeed where stored the proper way?

Generally they don't, until something happens that reveals the contrary. Like the Cambridge Analytica fiasco.

Re: GDPR: Don't Panic

#298

Exactly. People try to explain to me how it is impossible to comply and usually it turns out that it would be easy. I think the problem most of time that people misunderstanding the requirements or not reading GDPR (not even TLDR versions).

There is no "TLDR" of the GDPR. It has to all be read, understood and complied with. This is basic legal compliance, and is not at all easy for a small business.

[deleted]

Re: GDPR: Don't Panic

#299
post #251

> The GDPR will require me to hire people and my entity is too small to be able to afford this Q: Does my business need to appoint a Data Protection Officer (DPO)? A: DPOs must be appointed in the case of: (a) public authorities, (b) organizations that engage in large scale systematic monitoring, or (c) organizations that engage in large scale processing of sensitive personal data (Art. 37). If your organization does…

There is a legitimate question here, where does "large scale" begin? There are a lot of similar questions that nobody can personally guarantee they know the answers for.

In the GDPR draft it was "250 employees or with 5000 records." but 5000 records was dropped.

Now it says:

http://data.consilium.europa.eu/doc/document/ST-5419-2016-IN...

>The obligations referred to in paragraphs 1 and 2 shall not apply to an enterprise or an organisation employing fewer than 250 persons unless the processing it carries out is likely to result in a risk to the rights and freedoms of data subjects, the processing is not occasional, or the processing includes special categories of data as referred to in Article 9(1) or personal data relating to criminal convictions and offences referred to in Article 10.

Basically small firm that is just holding minimum amount of customer/user information and data and where the business model is not centered around profiling and processing user data.

Re: GDPR: Don't Panic

#300
As a solo business owner based in the US, I’ve been spending the last couple weeks learning about GDPR and getting compliant. While it has not been a fun process, I do think in general the regulation is quite reasonable and overall good for the world in general. So far, GDPR compliance has not cost me any money, only time.

There are three problems however that I have with GDPR and I’d love to hear how other small non-EU businesses are dealing with this.

First is the requirement to have EU representation (Art. 27). Since I don’t have any physical presence in the EU, GDPR requires the appointment of a representative. It would appear that a new industry has been created selling non-EU businesses GDPR representation in the EU which in my brief Google searching can cost $1000 per year or more. Are other small businesses owner out there paying for this? Or how else to deal with this requirement? Not a lawyer but this is the only part of GDPR I am tempted to ignore.

Second is the common practice of using lead magnets to collect emails for marketing. My email signup forms are very clear about marketing use, and are double opt in, and subscribers can opt out with a single click. But my research suggests that this is still not GDPR compliant unless there is an explicit consent, which I believe will reduce email signup rates. Also, while Mailchimp has a GDPR form, but it is quite large and doesn’t work embedded in web page headers, sidebars or popups. I’ve only seen one of these Mailchimp GDPR signups in the wild and they opened a new browser tab to present the hosted Mailchimp GDPR form which to me isn’t ideal. How are others handling email marketing signups? Disclosure and checkbox for consent seems a reasonable compromise but I haven’t seen this very often in the wild, at least not yet, that may change come May 25. Not a lawyer but I’m tempted to keep my current forms until I see more websites make changes.

Third, I have a medium sized mailing list (less than 10,000) mostly US based emails which is important for my business. Are people running consent campaigns (as suggested by Mailchimp?) I’m concerned that I will lose a substantial part of my list due to non-response. Again, the list is double opt in and I am very reasonable with my marketing emails. (Not a lawyer) but my thought is to segment my list into EU and non-EU customers and run a consent campaign only on EU emails. Has anyone run a consent campaign and how did it work out for you?

Any thoughts or suggestions from other small and solo business owners would be much appreciated.

Post reply on HN