Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

331–340 of 833 posts

Re: GDPR: Don't Panic

#331

As a solo business owner based in the US, I’ve been spending the last couple weeks learning about GDPR and getting compliant. While it has not been a fun process, I do think in general the regulation is quite reasonable and overall good for the world in general. So far, GDPR compliance has not cost me any money, only time. There are three problems however that I have with GDPR and I’d love to hear how other small non…

I suspect you’re going to get the predictable response here that you should do the most conservative things possible, and if that tanks your optin rates and email list and ultimately your business, then obviously you’re a filthy scammer and your business deserved to die.

The lead magnet thing is such a good example. It’s a clear and voluntary trade-off: you can have this free resource if you join my list, from which you can unsubscribe at any point. It can obviously be done in a scammy way, but you’re clearly not doing that. But some people think you should have to provide that resource without any restriction.

Or that forcing people who already opted in to do so again is fair, because if they don’t reconfirm, then they must not have wanted to be on the list. This is like a SaaS company calling every customer periodically to ask them if they might want to cancel.

It makes no sense, but the pro-GDPR crowd on HN in particular is very hostile to marketing in general and email marketing in particular.

No one here who likes the GDPR gives a shit about your business. They’ll be happy to give you bad advice based on how they wish the world was, and if it costs you dearly, that’s not their problem and you probably deserved it anyway.

I’m doing some of the same activities as you, and I personally will be changing basically nothing for GDPR. I’ve always treated customers fairly and I’ll continue to do so. Governments that have no jurisdiction or enforcement mechanisms against my company can pound sand.

Re: GDPR: Don't Panic

#333

For those of you understandably intimidated by the GDPR regulations themselves, here's a good summary in plain English: https://blog.varonis.com/gdpr-requirements-list-in-plain-eng... The UK's ICO also has a good structured summary: https://ico.org.uk/for-organisations/guide-to-the-general-da... In general I agree with the sentiments in this article. I've probably spent a total of three to four days reading around th…

I am concerned that the effect of this legislation on the private individual is the opposite of the stated intention. People are being forced to sign agreements which jeopardise the natural rights to their data which they would otherwise have. One example: a friend who has a very pretty daughter was asked by her school to give them the right to film her and to use any and all such recordings as they see fit for 50 ye…

Art.7(3): "The data subject shall have the right to withdraw his or her consent at any time."

https://gdpr-info.eu/art-7-gdpr/

Re: GDPR: Don't Panic

#334

Earlier quoted context omitted.

I'm not sure what you mean by "actually the minimum". They will find you the maximum of those two numbers, at most, if you flagrantly disregard the law.

Yeah, this is the confusion - it's difficult to write it out in a way that isn't ambiguous! I think the fact that there are two numbers, the higher of which is the maximum fine, may imply to some people that the lower figure is the minimum - i.e. if 4% of your global turnover is €100m then €20m is the minimum - but of course there in fact isn't a minimum. It might have helped comprehension if there had been an arbitr…

The problem with that is that it would introduce a minimum fine, where currently there doesn't need to be a fine at all (if you coöperate).

Re: GDPR: Don't Panic

#335

Earlier quoted context omitted.

There is nothing - and I do mean nothing - written into the GDPR that requires any warnings of any kind, or places any limits on fines, except for $10/$20 million or 4% of revenue, whichever is greater. Period. A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR. The idea that "yes it says that but we can trust EU regulators to not assess large fines against foreign…

>we can trust EU regulators I want to stress that this is a major point of political polarization in Europe at the moment. Even if this claim is true, it warrants a clear and articulated defense.

Also any Americans reading “we can trust X” will likely get a good laugh out of this.

It is irresponsible not to assume that if the law is written a certain way then at some point, the law can (and likely will) be enforced that way when it suits the government.

Re: GDPR: Don't Panic

#336
post #207

I've been doing a bit of consulting work on the GDPR and for the most part small sites aren't going to have a lot of headache dealing with the GDPR requirements. Typical, simplified, workflow (varies): 1) Review what data you collect and why 2) Document these in an updated privacy policy along with third parties you share data with and why 3) Update all forms on your site collecting personal information 4) Update you…

Privacy Shield starts at $500 per year for the smallest company, and that’s before you contract with a mediator (lowest cost there is $50/year if you use the EU options). Unless I’m missing the option for $250/year on their website?

I was referring to https://www.privacyshield.gov/Program-Overview where single framework (EU-U.S.) for companies with between $0-$5 million the yearly fee is $250. If you want to add Swiss-U.S. privacy shield as well, then $375 per year for both.

Re: GDPR: Don't Panic

#337
post #199

> I was actually surprised by how easy it is to read it there's a whole two hundred post debate around here whether ip are or aren't pii on their own, with the wast majority holding the wrong position. there's a whole branch of gdpr that people aren't considering, which is not related to software but to your business (i.e. your mail calendar). you also need a privacy policy if you are receiving phone calls. did you k…

No, people were correctly answering the specific question: is an IP address on its own personal data? (No, it can't be used to identify a natural person). THe problem is that it's a stupid question. No-one has just IP addresses, they have a mix of data. If you can combine the IP address with anything else to identify a natural person it becomes personal data.

Haha, the response to your comment here is a perfect example of how ambiguous this law is: you yourself are disagreeing with official interpretations of this law. And the blog post that we’re commenting on here says that personal projects have to comply, while you have posted multiple times saying they don’t?

It’d be really nice for the “fucking idiots” that you referred to earlier if those of you who clearly know what the law says and what it means could get your stories straight.

Re: GDPR: Don't Panic

#338

This article actually points out my philosophical problem with GDPR. In one point he says you have to be compliant if you want to do business in the EU. In another he observed that it is difficult (maybe impossible) to block EU folks from coming to a web presence. It’s the expansive reach that bugs me. I’ll note that for real businesses this is just a thought excercise, but it’s one I keep coming back to. What if som…

> This article actually points out my philosophical problem with GDPR. In one point he says you have to be compliant if you want to do business in the EU. In another he observed that it is difficult (maybe impossible) to block EU folks from coming to a web presence. It’s the expansive reach that bugs me.

Other countries have already had to deal with the US on this front. If you are a US national you may find it extremely hard to get a bank account in a non-US country, for example; non-US gambling services also have to be very careful about US users (PokerStars et al) https://en.wikipedia.org/wiki/United_States_v._Scheinberg

There are also things like the Magnitsky Act and various other bits of human rights law that allow extremely serious crime and crimes against humanity to be pursued internationally.

The one we'll have to watch out for are Chinese censorship laws going global. There's already some weird side effects of "One China".

Re: GDPR: Don't Panic

#339

For those of you understandably intimidated by the GDPR regulations themselves, here's a good summary in plain English: https://blog.varonis.com/gdpr-requirements-list-in-plain-eng... The UK's ICO also has a good structured summary: https://ico.org.uk/for-organisations/guide-to-the-general-da... In general I agree with the sentiments in this article. I've probably spent a total of three to four days reading around th…

There is nothing - and I do mean nothing - written into the GDPR that requires any warnings of any kind, or places any limits on fines, except for $10/$20 million or 4% of revenue, whichever is greater. Period. A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR. The idea that "yes it says that but we can trust EU regulators to not assess large fines against foreign…

I think you and everyone making similar points in this thread are getting tripped up by the difference between rules-based regulation and principles-based regulation. This is unsurprising, given that the US is so heavily rules-based, but the EU (certainly the UK) has a long history of principles-based regulation.

In rules-based regulation, all the rules are spelled out in advance, and the regulator is basically an automaton once the rules are set. In principles-based regulation, the rules are extensive rather than complete and you expect the regulator to have some lattitude (and, if the system is well designed, a mechanism of recourse if they do something stupid).

An advocate of rules-based regulation would say this can make regulators unpredictable and capricious. An advocate of principles-based regulation would say it is an important safeguard against "rules-lawyering" and regulatory capture (especially the kind that ties new entrants up in check-box compliance that doesn't actually affect your business because all the rules have been worked around).

A classic example would be the time PayPal tried to tell the UK regulators they shouldn't be regulated like a financial institution (which is a claim they successfully made in the US). They pointed to chapter and verse of the relevant law, and said that according to subparagraph 2.b.c(iii)... and the relevant regulator essentially told them "shut up, you keep consumers' money for them and will be treated accordingly". As a result, the worst "PayPal took all my money and I can't get it back" stories generally do not come from the UK. (And when they do, they are accompanied by referrals to the Financial Conduct Authority, who have teeth.)

You can approve of this way of working or not, but the GDPR is a principles-based regulation, and you'll have to engage with it on those terms.

Re: GDPR: Don't Panic

#340

Earlier quoted context omitted.

There is nothing - and I do mean nothing - written into the GDPR that requires any warnings of any kind, or places any limits on fines, except for $10/$20 million or 4% of revenue, whichever is greater. Period. A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR. The idea that "yes it says that but we can trust EU regulators to not assess large fines against foreign…

In principle I might agree with you, however the EU has a long history of striking a fair balance between consumer rights and commercial interests. There is no point, in history, of the EU doing anything remotely like you've described. Which actually gives me more faith in the GDPR than legislation in a corrupt ecosystem as corrupt individuals will find a way to warp legislation in their favor anyway. So yes, I do tr…

Related to this, there is a difference in culture that may had add to the fear for people running SMEs outside of Europe. I am talking about a difference in the culture of fines, at least at the local level of government based on my personal experience. When I lived in Canada (and the US briefly) it was common for me to get fined for various trivial offences. I used to joke I should have a fine budget, or at least fine schedule for attending court. The local authorities set speed traps, fine for crossing the road at the wrong place, not shoveling snow quickly etc. My parents in-law and everyone on their whole street got fined for parking their cars on the street by a by-law officer instead of their driveways when the houses were new builds still getting constructed and new drive ways were clearly in the process of being constructed and could not be entered. There was someone in the news who got arrested for not mowing their lawn. I'm not making this up, just do a search, in fact it seems dozens of people have been sent to jail for not paying fines for not keeping up with landscaping in the US. Now since being back in the UK for six years I've not received a single fine, had any interaction with the police or courts. There is a big difference in how fines are applied in Europe and I agree with your comment that I do trust the EU more in this regard, based on the way they operate historically.
Post reply on HN