How GDPR Will Change The Way You Develop
361–370 of 710 posts
Re: How GDPR Will Change The Way You Develop
#362Earlier quoted context omitted.
So nice to see progress in privacy but please someone explains how GDPR will help EU startups! GDPR is inevitably going to hinder any new company forced to abide by it. So the next Uber/Wechat will first flourish in US/China/Russia and then come to the EU, not the other way around. Entrepreneurs / investors also want their time & money to be used to build value first rather than solve yet another accidental complexit…
I wouldn't say marginal, but it is a lot easier to implement GDPR if you do it up-front, from day one. If you start off with a policy of just not collecting or storing information unless you've made a conscious decision that you really do need it, that's a huge start. From there, you your main obligations are to ensure that any personal data you do collect can be deleted at a reasonably granular level, and that you d…
Re: How GDPR Will Change The Way You Develop
#363Earlier quoted context omitted.
You attest so legally binding. The legal system does not function on mathematical proofs. If it turns out you did not speak the truth, you can be fined, and maybe even jailed. That's how it works. Also, we are not talking about forgetting someone personally, but deleting their data. I assume that's clear.
So if you're willing to indefinitely lie, you just get out? This seems inefficient.
Re: How GDPR Will Change The Way You Develop
#364In this article the author states: "The latter definition is important for developers. It includes things like IP addresses, mobile device IDs, browser fingerprints, RFID tags, MAC addresses, cookies, telemetry, user account IDs, and any other form of system-generated data which identifies a natural person.". This information does NOT automatically qualify as personal data. Information being unique is not the same as…
This doesn't make sense to me. Wouldn't that make every id that is one to one or one to many with a customer PII? That seems absurd. A user alias on some random site would meet that criteria, assuming they took name/address/etc when you signed up. Unless PII has some other significance than I'm interpretting it to have?
Re: How GDPR Will Change The Way You Develop
#365Re: How GDPR Will Change The Way You Develop
#366Earlier quoted context omitted.
> Sounds like you have a legitimate interest in logging IP addresses for security purposes European legislation demands this in fact. You have to keep the logs for a few months.
What European legislation is that?
Apparently no longer in effect (overthrown)
Re: How GDPR Will Change The Way You Develop
#367Earlier quoted context omitted.
People will just add a checkbox that the customer must check to complete the transaction: [] I affirm that I an not an EU citizen.
That's not possible according to GDPR. Edit: downvotes? Really? Did you guys read the law at all?
Re: How GDPR Will Change The Way You Develop
#368Earlier quoted context omitted.
Not quite. GDPR applies to you, a US entity, if you do business with an EU citizen trading in dollars living in the US.
"[...]Whereas the mere accessibility of the controller's, processor's or an intermediary's website in the Union, of an email address or of other contact details, or the use of a language generally used in the third country where the controller is established, is insufficient to ascertain such intention, factors such as the use of a language or a currency generally used in one or more Member States with the possibilit…
Re: How GDPR Will Change The Way You Develop
#369Earlier quoted context omitted.
€20mil is the maximum, and there are lower tiers for lesser infractions. That is a figure used to bring non-European companies who wish to trade in the EEA but not comply to the negotiating table. We rarely see the largest tier of fines here in the UK, I'd expect little to change there too. Reputational damage should be a focus of anyone concerned with risk here.
Not really true :) $20mil or 4% global revenue whichever is higher. $20mil is nothing for ggl/fb/... This time EU did it right, I doubt some small local shop will ever get max punishment but the % of global revenue is on the other side still something that can bite global corporations.
Why? It's selective prosecution, plain and simple.
These things have a history of being selectively used to punish institutions for other reasons that are not easy to do using the law
To the people downvoting, imagine the following scenario:
Website promotes ideas the EU finds problematic. The EU wants to silence it but can't because of free-speech laws or any other constraint.
All they have to do is find something trivial under this law and punish them for it, bankrupting the company.
All of these "I hope the law will be applied reasonably" are dangerous because they give the state too much power.
Re: How GDPR Will Change The Way You Develop
#370Earlier quoted context omitted.
There's a big difference between "in the EU" and "with people who reside in the EU". When I come to the EU to do business, sure, I'll comply with their laws. But it's very different to expect people who live outside the EU to respect EU laws, just because someone from the EU happens to choose to visit their website. I don't see this as any different than if someone in the EU was to visit a convenience store in the US…
The comparison to the convenience store fails because in the digital realm, the customer does not need to physically travel outside the EU to do business with somebody outside the EU. Or, to look at it another way: If it weren't extraterritorial, ad providers (for example) could simply close their local branches, and EU citizens would not be protected from consent-less data gathering. To realistically be able to fulf…