This article actually points out my philosophical problem with GDPR. In one point he says you have to be compliant if you want to do business in the EU. In another he observed that it is difficult (maybe impossible) to block EU folks from coming to a web presence. It’s the expansive reach that bugs me. I’ll note that for real businesses this is just a thought excercise, but it’s one I keep coming back to. What if som…
GDPR: Don't Panic
321–330 of 833 posts
Re: GDPR: Don't Panic
#322Earlier quoted context omitted.
In England and Wales, you could be fined £10^99 for having a crumb of cannabis in your pocket. There is nothing - and I do mean nothing - written in the Misuse of Drugs Act that requires any warnings of any kind, or places any limits on fines. The maximum sentence for possession of a Class B controlled substance is five years imprisonment and an unlimited fine. Period. A fine larger than the number of atoms in the un…
Yes, but the point I'm trying to get across to people is that there's a general legal requirement that the legal and administrative systems be proportionate, even if it's not incorporated by explicit reference in every piece of legslative text. (I can't lay hands on it at the moment but there are clear guidelines to UK judges on what constitutes reasonable fines for offences, such that it should be feasible for the p…
Re: GDPR: Don't Panic
#323Earlier quoted context omitted.
> The problem of multiple ambiguities in GDPR hasn't really been addressed here. Such as? > Also, must be nice to live in a country where the regulator is as benevolent and reasonable as is described in this article. It is, thanks.
OTOH - Scope outside of Europe – e.g. if a completely foreign entity that offers a Spanish or French translation of its service could potentially be covered by GDPR, even if they're not marketing to EU markets specifically. Too bad for Quebec I guess. Or what if you fly to speak at a conference in Europe – is that "marketing" to residents of EU? Depends on your slides? Or not? Who knows. - Consent – does X fall under…
No, the GDPR is clear that it is applicable if you are offering goods or services to Europeans. The fact you are speaking French in Quebec isn't relevant.
> Or what if you fly to speak at a conference in Europe – is that "marketing" to residents of EU? Depends on your slides? Or not? Who knows.
So, if you fly to the European conference and talk to a Europeam audience, you're not going to be covered by the GDPR until you actually supply goods or services within the EU.
Re: GDPR: Don't Panic
#324My vocabulary has been enriched with a new word: PII. I like it. It simplifies when thinking about GDPR. I expect one or two years from now I'll know the important parts of GDPR like the back of my hand.
But right now every person in the world running a multinational company needs to understand a new piece of legislature that threatens 4% of their annual revenue. You have better things to do and so I understand everyone's anger.
But is it wrong to force business-runners to learn about GDPR, stuff that's pretty close to human rights, like "don't track any of my PII without telling me exactly what you plan to do with it"? Is it wrong to now have to learn this, as a web/app developer?
I'm sooooo sick of being tracked. It has definitely made me exit the social media world all together, six months ago. Even though it is detrimental to my career I even asked Linkedin to erase my data. I truly hope my career isn't screwed just because I refused to give Microsoft a detailed description of 30% of my person, my whole work life that they can connect to an email address (some people even give them their phone number), IP, tracking cookie, thus a Facebook profile, real or shadow, thus to the most detailed graph of PII there is, probably in the whole universe. Hopefully in the whole universe otherwise civilizations on other planets took a wrong step somewhere.
I hope GDPR leads to PII being treated as gold by the market because it's so rare. Because isnt' it better to skip all this tracking-business that having to deal withstuff like GDPR?
No cookies for me please. Ans I'm also sick of having to run javascript.
Re: GDPR: Don't Panic
#325Earlier quoted context omitted.
What ? It's the opposite, it allow you to access and delete the data, even if you gave consent one time. And your image concern a lot of other old laws, even if you sell it you can get it back later.
I have difficulty in understanding your language and in following your logic. Surely, signing away the rights to your records for over 50 years can not be better for you than not signing them?
Re: GDPR: Don't Panic
#326Earlier quoted context omitted.
No, people were correctly answering the specific question: is an IP address on its own personal data? (No, it can't be used to identify a natural person). THe problem is that it's a stupid question. No-one has just IP addresses, they have a mix of data. If you can combine the IP address with anything else to identify a natural person it becomes personal data.
And you’re wrong Ip are personal data https://ec.europa.eu/info/law/law-topic/data-protection/refo... Without conditions. Even hashing them doesn’t make them ‘irreversibly anonimized’ because the ip space is too small for hashing to be irreversible. A rainbow table can be built with all ips and use to deanonimize the ip.
> The law protects personal data regardless of the technology used for processing that data – it’s technology neutral and applies to both automated and manual processing, provided the data is organised in accordance with pre-defined criteria (for example alphabetical order). It also doesn’t matter how the data is stored – in an IT system, through video surveillance, or on paper; in all cases, personal data is subject to the protection requirements set out in the GDPR.
That raises an amusing question. Suppose you have a one person business with a small number of customers (a few dozen or so) that you deal with in person. With proper mnemonic techniques it would be possible to do all the storage and processing of their personal data in your head.
Does GDPR apply?
The only thing I see in the quoted paragraph that might suggest it does not is "provided the data is organised in accordance with pre-defined criteria (for example alphabetical order)". Do brains use pre-defined criteria to organize data?
This too raises an interesting question:
> Personal data that has been rendered anonymous in such a way that the individual is not or no longer identifiable is no longer considered personal data. For data to be truly anonymised, the anonymisation must be irreversible.
If data is used to train a neural net and then discarded, but you keep the trained neural net, in some sense the data is still there in the weights of the connections in the neural net. Has it been sufficiently rendered anonymous to no longer be considered personal data?
Re: GDPR: Don't Panic
#327Earlier quoted context omitted.
I really don't know why people think that the authorities will (or even could) automatically punish each minor infraction with 4 % of global revenue or 20 million €. GPDR article 87 specifies in great detail when fines should be imposed and how their value should be calculated, and the Article 29 WP also has a guideline on that: https://ec.europa.eu/newsroom/just/document.cfm?doc_id=47889 It is therefore simply not p…
I'm starting to wonder if there's an active disinformation campaign about this somewhere. Are people getting their fears from Facebook again? Edit: If there is such a thing I bet it's Cambridge Analytica/"SCL group" involved, since they made their money from large scale nonconsensual abuse of political personal data, and have an arm dedicated to swinging elections with misleading Facebook adverts.
Re: GDPR: Don't Panic
#328Here in UK I have been receiving about 5-10 emails a day from various companies - most of whom I don't remember - telling me I need to sign up again so they can keep my details and keep spamming me. Fantastic.
Re: GDPR: Don't Panic
#329I've been doing a bit of consulting work on the GDPR and for the most part small sites aren't going to have a lot of headache dealing with the GDPR requirements. Typical, simplified, workflow (varies): 1) Review what data you collect and why 2) Document these in an updated privacy policy along with third parties you share data with and why 3) Update all forms on your site collecting personal information 4) Update you…
Re: GDPR: Don't Panic
#330For those of you understandably intimidated by the GDPR regulations themselves, here's a good summary in plain English: https://blog.varonis.com/gdpr-requirements-list-in-plain-eng... The UK's ICO also has a good structured summary: https://ico.org.uk/for-organisations/guide-to-the-general-da... In general I agree with the sentiments in this article. I've probably spent a total of three to four days reading around th…
There is nothing - and I do mean nothing - written into the GDPR that requires any warnings of any kind, or places any limits on fines, except for $10/$20 million or 4% of revenue, whichever is greater. Period. A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR. The idea that "yes it says that but we can trust EU regulators to not assess large fines against foreign…
There's nothing that says IRS won't prosecute you if someone buys you a soda and you don't declare it as income.
Or that you won't be prosecuted by someone in the US if your blog has a copyrighted image and you don't receive a DMCA request that was sent to you.
See how ridiculous that sounds?
All fines can be administratively and judicially appealed.