Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

311–320 of 833 posts

Re: GDPR: Don't Panic

#311
post #79

Earlier quoted context omitted.

That Varonis link gets posted quite a bit, but it drastically over simplifies things and even tries to poke fun at some aspects of the legislation. The ICO site is a much better read for this.

Fair point - my intent was to point out that some sources which are less intimidating than others. If all you read was the Varonis link you'd be in trouble, but if someone's the kind of person who thinks that they can read one blog post and understand the GDPR I'm not sure they're the kind of person that can be helped anyway...

I would even go as far as saying that that article is straight up wrong/misinterpreting at least some of the articles.

I randomly checked Article 14, as I am wondering how I am expected to communicate to users that I don't collect any PII([0]), and it turns out Article 14 is not about

"You need to tell people what you’re doing even if you’re not collecting personal data."

but about

"Information to be provided where personal data have not been obtained from the data subject" = "You have collected personal data about the data subject, just not directly from them, but via some other source"

[0]: Even though I'm not sure if that's even easily possible for any company that has a website, now that IPs can fall under PII.

Re: GDPR: Don't Panic

#312

Earlier quoted context omitted.

And that is a good thing. This >23 different trackers and adservers just to read crappy news content BS is so nice to be shaken. I really love the GDPR for just making the life for such business models way harder. Implementing data, analytics, tracking and stuff in a way that is compliant with GDPR (or its local equivalents) is doable and from an architectural point of view even interesting imho. I love building GDPR…

i suggest you remove the 3 trackers from your blog, or at least let me see it without them. I m not trying to be snarky, just pointing out that removing everything is often very hard.

Well. I know that I have GTM, GA with DC integration (currently) still active on my blog. DC integration will be dropped and the privacy page will be updated to describe, what I am tracking and how long data is being stored. As needed to comply with GDPR/DSGVO.

As I am still having 7 days to go and that is just a personal blog, I plan on using my free time to do that (would just take 3 - 5 minutes to disable everything if I wanted to by removing GTM and redeploying).

So removing everything is quite easy. It is way more difficult to selectively remove singular features - in this case the DoubleClick integration. As I am not doing that exact step all day (even being a data analyst with a focus on web data), I would have to look, where to configure that exactly. That would take longer.

So be snarky - I don't care, as I am already preparing for GDPR compliance and will have my house in order come May, 25th.

[Edit] Took 12 minutes in the end. Will take some time until caching catches up. Using a incognito instance all good to go regarding the trackers. "Only" the update for the privacy page remains for the weekend to do.

Re: GDPR: Don't Panic

#313

For those of you understandably intimidated by the GDPR regulations themselves, here's a good summary in plain English: https://blog.varonis.com/gdpr-requirements-list-in-plain-eng... The UK's ICO also has a good structured summary: https://ico.org.uk/for-organisations/guide-to-the-general-da... In general I agree with the sentiments in this article. I've probably spent a total of three to four days reading around th…

> I've probably spent a total of three to four days reading around the GDPR and I don't really see what's special about this law other than it's imposing decent standards on what was in effect a wildly unregulated industry in people's personal data We are still waiting for the first court battles that will help determine how GDPR is actually enforced in practice. Until then being in compliance with GDPR is gonna be l…

> We are still waiting for the first court battles that will help determine how GDPR is actually enforced in practice.

I'm wondering if this is yet another point where cultural differences are muddling the discussion. In particular, the difference between common law systems (like the USA) and civil law systems (like nearly all of the EU).

Re: GDPR: Don't Panic

#314

Earlier quoted context omitted.

i suggest you remove the 3 trackers from your blog, or at least let me see it without them. I m not trying to be snarky, just pointing out that removing everything is often very hard.

The site linked in their profile works just fine with all JS disabled.

Thanks. I tried to achieve that. As I am surfing with a lot of JS being blocked/disabled, I wanted my own site to be usable for myself.

Re: GDPR: Don't Panic

#315

For those of you understandably intimidated by the GDPR regulations themselves, here's a good summary in plain English: https://blog.varonis.com/gdpr-requirements-list-in-plain-eng... The UK's ICO also has a good structured summary: https://ico.org.uk/for-organisations/guide-to-the-general-da... In general I agree with the sentiments in this article. I've probably spent a total of three to four days reading around th…

There is nothing - and I do mean nothing - written into the GDPR that requires any warnings of any kind, or places any limits on fines, except for $10/$20 million or 4% of revenue, whichever is greater. Period. A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR. The idea that "yes it says that but we can trust EU regulators to not assess large fines against foreign…

In England and Wales, you could be fined £10^99 for having a crumb of cannabis in your pocket. There is nothing - and I do mean nothing - written in the Misuse of Drugs Act that requires any warnings of any kind, or places any limits on fines. The maximum sentence for possession of a Class B controlled substance is five years imprisonment and an unlimited fine. Period. A fine larger than the number of atoms in the universe is perfectly lawful under the Misuse of Drugs Act. The idea that we can trust judges and sentencing guidelines rings hollow to me.

Re: GDPR: Don't Panic

#316

Earlier quoted context omitted.

I'm unhappy with this because now I have to do a lot of extra work verifying that I'm not breaking some law, then implement changes in both code and license agreements, then get all the users to agree. I've had zero profit from user data so far - to the contrary. If everyone could be billed just with some cryptocurrency, totally anonymous, that would be great .

The only thing I can do as a customer is be mildly amused at the fact that you're complaining it's inconvenient for you to respect my privacy now that a law is coming into effect forcing you to do so. From the other end of the spectrum, I know you're wildly exaggerating the difficulty of compliance.

It's not inconvenient, it's costing me money. I don't want your data, I need to collect it and store it to comply with other laws, now I need to verify that the particular way I collect and store that data isn't violating some other new law.

You are not my customer, but even if you were, keep in mind that for every piece of regulation (and there's tons of it!) I need to fulfill, I have to pay, which means you need to pay. I need to set prices to keep my bottom line. If I can't keep my bottom line, I'll eventually stop providing the service, because I'm not providing it for fun. That's for paid services.

Now, some companies don't even charge you, they provide (aggregate) data about you to advertisers, who are then willing to pay more for their ads. It only makes sense, how much would you pay for an ad for a piece of specialized software that gets shown to the wrong audience 99.99% of the time? What's going to happen if that kind of data usage becomes infeasible? Those companies need to start charging, or go out of business. There will be less free services. I suppose that helps companies who do charge, but it hurts people who can't pay and don't care about data collection.

I'm not providing such a service, but if I was, you would be paying me with your "privacy". If "respecting your privacy" means you don't want to pay, you can get lost, because you're only costing money. The definition of "customer" is that you compensate the other side.

Re: GDPR: Don't Panic

#317

Earlier quoted context omitted.

There is nothing - and I do mean nothing - written into the GDPR that requires any warnings of any kind, or places any limits on fines, except for $10/$20 million or 4% of revenue, whichever is greater. Period. A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR. The idea that "yes it says that but we can trust EU regulators to not assess large fines against foreign…

In England and Wales, you could be fined £10^99 for having a crumb of cannabis in your pocket. There is nothing - and I do mean nothing - written in the Misuse of Drugs Act that requires any warnings of any kind, or places any limits on fines. The maximum sentence for possession of a Class B controlled substance is five years imprisonment and an unlimited fine. Period. A fine larger than the number of atoms in the un…

Yes, but the point I'm trying to get across to people is that there's a general legal requirement that the legal and administrative systems be proportionate, even if it's not incorporated by explicit reference in every piece of legslative text.

(I can't lay hands on it at the moment but there are clear guidelines to UK judges on what constitutes reasonable fines for offences, such that it should be feasible for the person to actually pay the fine)

Re: GDPR: Don't Panic

#318

Earlier quoted context omitted.

i suggest you remove the 3 trackers from your blog, or at least let me see it without them. I m not trying to be snarky, just pointing out that removing everything is often very hard.

The site linked in their profile works just fine with all JS disabled.

i did not mean that the site doesnt work without tracking, but according to the law i should have the option to access the site without being tracked.

Re: GDPR: Don't Panic

#319
post #303

Earlier quoted context omitted.

You can litigate disproportionate fines, and there's a general requirement for proportionality in both EU law and under the ECHR. Again, people are assuming that this is the first and only directive that has fines associated with it. It isn't. You don't hear a lot of people talking about the three month prison sentences possible for CE marking, for example - because very few of them have been handed out and only for…

You can litigate disproportionate fines Who's to say that 10% of the maximum for a minor violation isn't proportionate? Also, most small businesses do not have the resources to hire competent counsel on the other side of the planet to litigate these things.

> Who's to say that 10% of the maximum for a minor violation isn't proportionate?

A large body of case law, well-defined guidelines for evaluating harms and mapping them to fines, and the EU's general fear of stymieing economically productive activity (the motivation behind GDPR is to enable more data trading, not less, but within better-defined legal boundaries).

We have had laws with "open ended" sentencing guidelines since the very beginning of organised society. This is a solved problem.

Re: GDPR: Don't Panic

#320
post #145

Earlier quoted context omitted.

Maximum possible fine for repeated worst possible violation after ignoring previous attempts at regulation and not making changes after previous smaller fines. It's not a minimum.

>Maximum possible fine for repeated worst possible violation after ignoring previous attempts at regulation and not making changes after previous smaller fines. Nothing in the GDPR states this. It's obviously the intent , but ultimately it's left up to the bon vouloir of EU regulators. It is perfectly legal under the GDPR to make an example out of you by levying the maximum fine for a first offense, and without warni…

>It is perfectly legal under the GDPR to make an example out of you by levying the maximum fine for a first offense, and without warning.

No it isn't. Read Article 83.

https://gdpr-info.eu/art-83-gdpr/

Post reply on HN