Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

351–360 of 833 posts

Re: GDPR: Don't Panic

#351

Earlier quoted context omitted.

There is nothing - and I do mean nothing - written into the GDPR that requires any warnings of any kind, or places any limits on fines, except for $10/$20 million or 4% of revenue, whichever is greater. Period. A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR. The idea that "yes it says that but we can trust EU regulators to not assess large fines against foreign…

That is absurd and wrong. The law says the fine needs to be proportionate: GDPR 83.1: Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this Article in respect of infringements of this Regulation referred to in paragraphs 4, 5 and 6 shall in each individual case be effective, proportionate and dissuasive.

Proportionate is in the eye of the beholder. As I stated in another response, an example might be that a low-level offense receives a fine of only 10% of the maximum - just $2 million. And apparently I don't need to worry, because I can just spend six figures hiring an attorney in a country I've never been to, who possibly speaks a language I don't, who will fight the case for me if the fine is out of line.

Sounds very workable.

Re: GDPR: Don't Panic

#352
post #145

Earlier quoted context omitted.

Maximum possible fine for repeated worst possible violation after ignoring previous attempts at regulation and not making changes after previous smaller fines. It's not a minimum.

>Maximum possible fine for repeated worst possible violation after ignoring previous attempts at regulation and not making changes after previous smaller fines. Nothing in the GDPR states this. It's obviously the intent , but ultimately it's left up to the bon vouloir of EU regulators. It is perfectly legal under the GDPR to make an example out of you by levying the maximum fine for a first offense, and without warni…

Article 29 states this.[0]

[0] https://ec.europa.eu/newsroom/just/document.cfm?doc_id=47889

Re: GDPR: Don't Panic

#353

Earlier quoted context omitted.

Yes and there's nothing saying I won't be arrested and thrown into a cell for the rest of my life if I say something incorrect by mistake when entering the US. There's nothing that says IRS won't prosecute you if someone buys you a soda and you don't declare it as income. Or that you won't be prosecuted by someone in the US if your blog has a copyrighted image and you don't receive a DMCA request that was sent to you…

Yes and there's nothing saying I won't be arrested and thrown into a cell for the rest of my life if I say something incorrect by mistake when entering the US. That simply isn't true. That would probably be considered lying to a federal agent. There are strict federal sentencing guidelines that spell out exactly what the sentence should be based on several factors . This is how civilized laws work - you don't simply…

You're right, laws in Europe are uncivilized, maybe that's why they have the highest rate of incarceration in the world.

Re: GDPR: Don't Panic

#354

This article actually points out my philosophical problem with GDPR. In one point he says you have to be compliant if you want to do business in the EU. In another he observed that it is difficult (maybe impossible) to block EU folks from coming to a web presence. It’s the expansive reach that bugs me. I’ll note that for real businesses this is just a thought excercise, but it’s one I keep coming back to. What if som…

'Doing business' requires two steps:

1. Invitation to treat: that is offering services for consumption

2. Offer to contract: fulfilling the invitation by making a contract of terms

If you drop a potential customer at step 1, e.g. having your web-server decline the connection based on GeoIP, would that not constitute reasonable effort? We don't have case law regarding GDPR yet but I would certainly argue that it shows efforts being taken to exclude EU residents.

Re: GDPR: Don't Panic

#355
Does anybody know if it's required to remove CDN links (such for Google fonts, cdnjs, etc.) and host all assets locally instead unless consent is given? Assets from CDNs are required for a site to function; what's not required is to send `Referer:` so maybe it's sufficient to set a referrer-policy.

Re: GDPR: Don't Panic

#356

Earlier quoted context omitted.

> Who's to say that 10% of the maximum for a minor violation isn't proportionate? A large body of case law, well-defined guidelines for evaluating harms and mapping them to fines, and the EU's general fear of stymieing economically productive activity (the motivation behind GDPR is to enable more data trading, not less, but within better-defined legal boundaries). We have had laws with "open ended" sentencing guideli…

It's like people are only now discovering that they are in fact living in a well structured society.......

There's a lot of American libertarians that believe government is intrinsically bad, for some reason. And also a monolith; they don't see any difference between bits of government, different branches, different types of enforcement, and so on. They're very loath to admit that it takes a certain minimum amount of structure to keep the roads open and the lights on.

Re: GDPR: Don't Panic

#357

Earlier quoted context omitted.

Yes and there's nothing saying I won't be arrested and thrown into a cell for the rest of my life if I say something incorrect by mistake when entering the US. That simply isn't true. That would probably be considered lying to a federal agent. There are strict federal sentencing guidelines that spell out exactly what the sentence should be based on several factors . This is how civilized laws work - you don't simply…

You're right, laws in Europe are uncivilized, maybe that's why they have the highest rate of incarceration in the world.

GDPR is extremely uncivilized. Forgetting the absurd fines and burdens it places on companies for a moment, consider the extraterritorial reach that EU is claiming for itself. The EU has declared itself Grand Emperor of the Internet.

Wars have been fought over less.

Re: GDPR: Don't Panic

#358

For those of you understandably intimidated by the GDPR regulations themselves, here's a good summary in plain English: https://blog.varonis.com/gdpr-requirements-list-in-plain-eng... The UK's ICO also has a good structured summary: https://ico.org.uk/for-organisations/guide-to-the-general-da... In general I agree with the sentiments in this article. I've probably spent a total of three to four days reading around th…

There is nothing - and I do mean nothing - written into the GDPR that requires any warnings of any kind, or places any limits on fines, except for $10/$20 million or 4% of revenue, whichever is greater. Period. A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR. The idea that "yes it says that but we can trust EU regulators to not assess large fines against foreign…

> A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR

Come on, this is just scaremongering. Newsflash: If you run a business, you are already responsible for adhering to hundreds of other laws in which the fines could reach millions. But you don't see people running around screaming that the world is ending, because they know that the laws will generally be applied fairly, given that a large economy (like that of the EU) relies on just application of laws to maintain stability.

Running a business, like anything else in life, requires the ability to make reasoned choices from somewhat ambiguous data. And the data here is somewhat ambiguous for good reason - it's to prevent businesses from exploiting loopholes and rendering the law ineffective. If you are going to crank the anxiety to 10 every time a situation like this occurs, you probably shouldn't be running a business or handling others' data in the first place.

Re: GDPR: Don't Panic

#359

Earlier quoted context omitted.

I read that GDPR applies to EU residents. That means someone who is EU resident non necessarily could be browsing from the EU. For example when on holidays.

Yes, but you cannot check whether a person is a resident unless you explicitly ask them. There are no "public" API. It's much easier and safer to just assume someone who's in Europe is a resident, rather than figuring out if they really are. GDPR only applies to EU residents, yes, but not if they're on ex. holiday outside of EU. Say, a EU citizen is on holiday in The U.S. In such case the EU citizen is not protected…

> GDPR only applies to EU residents, yes, but not if they're on ex. holiday outside of EU.

While this is an interesting way to interpret it, it's likely that the law may be clarified in the future to state that if at the time of collecting their data the user is in the EU, the protections shall apply to said data regardless of where the user is now.

Re: GDPR: Don't Panic

#360

Earlier quoted context omitted.

There is nothing - and I do mean nothing - written into the GDPR that requires any warnings of any kind, or places any limits on fines, except for $10/$20 million or 4% of revenue, whichever is greater. Period. A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR. The idea that "yes it says that but we can trust EU regulators to not assess large fines against foreign…

I think you and everyone making similar points in this thread are getting tripped up by the difference between rules-based regulation and principles-based regulation. This is unsurprising, given that the US is so heavily rules-based, but the EU (certainly the UK) has a long history of principles-based regulation. In rules-based regulation, all the rules are spelled out in advance, and the regulator is basically an au…

This is it. Thank you, I commented about my local experiences with government in Europe and US/Canada but did not know the correct terms and you're right, I think this is the big difference and a driver of fear outside of the EU. In Canada I found the police, by-law enforcers, and almost any official are essentially rules based robots, very much different to my experience in the UK. Thank you for teaching me about rules-based and principles-based regulation. This is one of the big reasons I enjoy living in Europe tbh, a bit of discretion and old 'common sense' is actually quite an awesome thing.
Post reply on HN