Here in UK I have been receiving about 5-10 emails a day from various companies - most of whom I don't remember - telling me I need to sign up again so they can keep my details and keep spamming me. Fantastic.
I have a lot of companies emailing me saying I can opt-out, I thought that was the opposite of what the law is saying? Eg. If you continue using our service after 23th of May you automatically agree to the new terms. Huh?
GDPR: Don't Panic
341–350 of 833 posts
Re: GDPR: Don't Panic
#342For those of you understandably intimidated by the GDPR regulations themselves, here's a good summary in plain English: https://blog.varonis.com/gdpr-requirements-list-in-plain-eng... The UK's ICO also has a good structured summary: https://ico.org.uk/for-organisations/guide-to-the-general-da... In general I agree with the sentiments in this article. I've probably spent a total of three to four days reading around th…
There is nothing - and I do mean nothing - written into the GDPR that requires any warnings of any kind, or places any limits on fines, except for $10/$20 million or 4% of revenue, whichever is greater. Period. A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR. The idea that "yes it says that but we can trust EU regulators to not assess large fines against foreign…
GDPR 83.1: Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this Article in respect of infringements of this Regulation referred to in paragraphs 4, 5 and 6 shall in each individual case be effective, proportionate and dissuasive.
Re: GDPR: Don't Panic
#343Here in UK I have been receiving about 5-10 emails a day from various companies - most of whom I don't remember - telling me I need to sign up again so they can keep my details and keep spamming me. Fantastic.
I have a lot of companies emailing me saying I can opt-out, I thought that was the opposite of what the law is saying? Eg. If you continue using our service after 23th of May you automatically agree to the new terms. Huh?
Re: GDPR: Don't Panic
#344Interesting: I have a number of anti-GDPR comments here and on last night’s GDPR thread that got upvotes last night US-time, heavily downvoted throughout the night, and are now going back up :)
Re: GDPR: Don't Panic
#345Earlier quoted context omitted.
You can litigate disproportionate fines Who's to say that 10% of the maximum for a minor violation isn't proportionate? Also, most small businesses do not have the resources to hire competent counsel on the other side of the planet to litigate these things.
> Who's to say that 10% of the maximum for a minor violation isn't proportionate? A large body of case law, well-defined guidelines for evaluating harms and mapping them to fines, and the EU's general fear of stymieing economically productive activity (the motivation behind GDPR is to enable more data trading, not less, but within better-defined legal boundaries). We have had laws with "open ended" sentencing guideli…
Re: GDPR: Don't Panic
#346Earlier quoted context omitted.
There is nothing - and I do mean nothing - written into the GDPR that requires any warnings of any kind, or places any limits on fines, except for $10/$20 million or 4% of revenue, whichever is greater. Period. A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR. The idea that "yes it says that but we can trust EU regulators to not assess large fines against foreign…
Yes and there's nothing saying I won't be arrested and thrown into a cell for the rest of my life if I say something incorrect by mistake when entering the US. There's nothing that says IRS won't prosecute you if someone buys you a soda and you don't declare it as income. Or that you won't be prosecuted by someone in the US if your blog has a copyrighted image and you don't receive a DMCA request that was sent to you…
That simply isn't true. That would probably be considered lying to a federal agent. There are strict federal sentencing guidelines that spell out exactly what the sentence should be based on several factors . This is how civilized laws work - you don't simply say "max is $20 million, good luck everybody!"
Re: GDPR: Don't Panic
#347Earlier quoted context omitted.
The site linked in their profile works just fine with all JS disabled.
i did not mean that the site doesnt work without tracking, but according to the law i should have the option to access the site without being tracked.
These so called cookie layers are not necessary for tracking. They are not even necessary for first party on site advertising. For that you also do not need consent if you read the GDPR/DSGVO (German version).
In the DSGVO it is §6.1f [1] you would want to read about. There is even an elaborate explanation from the German legistlation [2] what "Berechtiges Interesse" ( legitimate interest) exactly means.
So to make this short: direct marketing as well as tracking is totally fine even without consent. Give an option to opt out, explain why you need the data, what you do with it and how long you store it as well as a point of contact (for people wishing for their data to be deleted) and you are fine.
As long as you do not do profiling or stuff like that. A personal blog/website is then totally fine with GDPR. Btw. you would need to add all of this to your privacy page even if you had no web tracking installed, as your webserver probably would have logging activated. Having an IP address in there make this data fall under the GDPR (at least in Germany). So you would need to explain all that stuff because of the log files non the less.
[0]: https://schriftrolle.de/datenschutz [1]: https://dsgvo-gesetz.de/art-6-dsgvo/ [2]: https://dsgvo-gesetz.de/erwaegungsgruende/nr-47/
[Edit:] Ordered the footnotes
Re: GDPR: Don't Panic
#348Earlier quoted context omitted.
In the GDPR draft it was "250 employees or with 5000 records." but 5000 records was dropped. Now it says: http://data.consilium.europa.eu/doc/document/ST-5419-2016-IN... >The obligations referred to in paragraphs 1 and 2 shall not apply to an enterprise or an organisation employing fewer than 250 persons unless the processing it carries out is likely to result in a risk to the rights and freedoms of data subjects, th…
The piece of text you're quoting is referring to obligations of keeping "Records of processing activities", and is not the definition of large scale, which is undefined in the GDPR.
http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=OJ:L:2...
>Staff headcount and financial ceilings determining enterprise categories
> 1. The category of micro, small and medium-sized enterprises (SMEs) is made up of enterprises which employ fewer than 250 persons and which have an annual turnover not exceeding EUR 50 million, and/or an annual balance sheet total not exceeding EUR 43 million.
Re: GDPR: Don't Panic
#349I was hoping for a nice respite to the anti-GDPR stuff we've seen recently, but this is just naked propaganda. In particular, the sentence: "the GDPR has the potential to escalate to those levels but in the spirit of the good natured enforcers ..." The author seems to have the idea that bureaucratic EU systems are inherently "good" and that even if things look bad on paper, it will be fine because they are "good" peo…
My chief concern is that this will end up being an instrument wielded by big business (through political connections) at the expense of smaller companies, especially smaller overseas competitors but also domestically. If EU-US relations continue to sour, it could also become a weapon in a hypothetical trade war, which I guess is probably one of the "benefits" from an EU government perspective.
Codifying privacy protection is important, but GDPR favors big companies and governments too strongly over already risk-burdened entrepreneurs.
Re: GDPR: Don't Panic
#350Dont panic. Panic when you get something like this. https://www.linkedin.com/pulse/nightmare-letter-subject-acce... Bottom line, DONT store/sell/mangle with personal data of your users unless you are able to fulfill this. I was thinking a bit about having an online store: - make login as it is on Hacker News, you dont need email - once user has selected and payed the goods, request sending address and contact (phone/…