Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

301–310 of 833 posts

Re: GDPR: Don't Panic

#301
post #71

Earlier quoted context omitted.

Geolocation, IP Lookup etc. You generally shouldn't care whether they're a resident in the EU, but just whether they are in EU or not. Remember GDPR doesn't cover any citizens from EU who aren't in EU.

I read that GDPR applies to EU residents. That means someone who is EU resident non necessarily could be browsing from the EU. For example when on holidays.

Yes, but you cannot check whether a person is a resident unless you explicitly ask them. There are no "public" API.

It's much easier and safer to just assume someone who's in Europe is a resident, rather than figuring out if they really are.

GDPR only applies to EU residents, yes, but not if they're on ex. holiday outside of EU.

Say, a EU citizen is on holiday in The U.S.

In such case the EU citizen is not protected by GDPR.

Re: GDPR: Don't Panic

#302
post #275
post #271

Earlier quoted context omitted.

GDPR requires those organisations to appoint a DPO, not to hire anyone new. It's like when you designate Ben to answer the phone after 5PM, Lisa to water the plants and the last guy to leave the office to turn off the light and close the windows (and for many companies there will be a lot less work involved with being a DPO, than with switching off the lights).

Exactly. Most businesses will already be required to have several "responsible person" roles for e.g. health and safety and fire evacuations. It's just that in a 1-person business they're all the same person.

Most small companies (below 10 employees) will refrain from appointing a DPO claiming that they don't do large scale systematic monitoring (not clearly defined).

The issue however is that for a DPO you need to avoid conflict of interest, as the DPO should be as independent as possible, even though the DPO could be an employee of the company.

Shareholders, C-level execs, employees that establish means and purposes of processing or handle the actual processing cannot be reasonably expected to place the interests of the data subject(s) above those of the company.

See article 38 for reference.

Re: GDPR: Don't Panic

#303
post #291

Earlier quoted context omitted.

There is actually an over-arching requirement for proportionality in all EU regulation: https://ukhumanrightsblog.com/2015/06/27/supreme-court-on-eu...

But that is in the eye of the beholder. With a maximum fine of $20 million, a country like Germany might say, for example, "Ok, small American company, yours was a minor violation. We'll only assess a $2 million fine - that's only 10% of the maximum! See how lenient and proportional we are? Danke und tschüss!"

You can litigate disproportionate fines, and there's a general requirement for proportionality in both EU law and under the ECHR.

Again, people are assuming that this is the first and only directive that has fines associated with it. It isn't. You don't hear a lot of people talking about the three month prison sentences possible for CE marking, for example - because very few of them have been handed out and only for egregious violations such as unsafe machinery that has caused injury.

Re: GDPR: Don't Panic

#304
post #299

Earlier quoted context omitted.

There is a legitimate question here, where does "large scale" begin? There are a lot of similar questions that nobody can personally guarantee they know the answers for.

In the GDPR draft it was "250 employees or with 5000 records." but 5000 records was dropped. Now it says: http://data.consilium.europa.eu/doc/document/ST-5419-2016-IN... >The obligations referred to in paragraphs 1 and 2 shall not apply to an enterprise or an organisation employing fewer than 250 persons unless the processing it carries out is likely to result in a risk to the rights and freedoms of data subjects, th…

The piece of text you're quoting is referring to obligations of keeping "Records of processing activities", and is not the definition of large scale, which is undefined in the GDPR.

Re: GDPR: Don't Panic

#305

Earlier quoted context omitted.

And that is a good thing. This >23 different trackers and adservers just to read crappy news content BS is so nice to be shaken. I really love the GDPR for just making the life for such business models way harder. Implementing data, analytics, tracking and stuff in a way that is compliant with GDPR (or its local equivalents) is doable and from an architectural point of view even interesting imho. I love building GDPR…

i suggest you remove the 3 trackers from your blog, or at least let me see it without them. I m not trying to be snarky, just pointing out that removing everything is often very hard.

The site linked in their profile works just fine with all JS disabled.

Re: GDPR: Don't Panic

#306

Earlier quoted context omitted.

There is nothing - and I do mean nothing - written into the GDPR that requires any warnings of any kind, or places any limits on fines, except for $10/$20 million or 4% of revenue, whichever is greater. Period. A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR. The idea that "yes it says that but we can trust EU regulators to not assess large fines against foreign…

In principle I might agree with you, however the EU has a long history of striking a fair balance between consumer rights and commercial interests. There is no point, in history, of the EU doing anything remotely like you've described. Which actually gives me more faith in the GDPR than legislation in a corrupt ecosystem as corrupt individuals will find a way to warp legislation in their favor anyway. So yes, I do tr…

[deleted]

Re: GDPR: Don't Panic

#307
post #303

Earlier quoted context omitted.

But that is in the eye of the beholder. With a maximum fine of $20 million, a country like Germany might say, for example, "Ok, small American company, yours was a minor violation. We'll only assess a $2 million fine - that's only 10% of the maximum! See how lenient and proportional we are? Danke und tschüss!"

You can litigate disproportionate fines, and there's a general requirement for proportionality in both EU law and under the ECHR. Again, people are assuming that this is the first and only directive that has fines associated with it. It isn't. You don't hear a lot of people talking about the three month prison sentences possible for CE marking, for example - because very few of them have been handed out and only for…

You can litigate disproportionate fines

Who's to say that 10% of the maximum for a minor violation isn't proportionate? Also, most small businesses do not have the resources to hire competent counsel on the other side of the planet to litigate these things.

Re: GDPR: Don't Panic

#308
The UK ICO will not push to fine if disclosure is provided within 14 days OR there is evidence to show attempts were made to secure data.

GDPR should only strike fear if the organisation/individual actively harvested data to sell without a Privacy Policy or market without an opt-out request.

The ICO also offers a free advisory service that anyone can petition for help in conforming to GDPR alongside training docs already mentioned in comments.

Re: GDPR: Don't Panic

#309

> • The GDPR will enable anybody to be able to sue me, even from abroad > The GDPR does not have this effect, but you may be interested to know that anybody can sue you or your business for whatever reason strikes their fancy. This is a direct consequence of doing business and has nothing to do with a particular law. What the GDPR allows private individuals to do is to contact their regulators and to complain if you…

People in Europe are not extremely litigious by nature and will likely resort to calling upon their supervisory authority instead of suing directly.

What is however very interesting is article 80, which will allow a data subject to mandate a not-for-profit body to seek judicial or non-judicial remedy on his/her behalf. This will give quite a bit of power to non-profit organisations built for this purpose and will likely add quite a bit of pressure to large companies that don't comply with the law.

Post reply on HN