Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

361–370 of 833 posts

Re: GDPR: Don't Panic

#361

Earlier quoted context omitted.

Hah, no. I guess you haven't dealt much with regulators in the past. Regulators can never be held to anything they say. When you ask questions, if they answer at all, it always comes with a disclaimer that it's merely "guidance" and not binding. If they later change their mind, it's always a "clarification" and not a change. The sort of people who think vague regulations are a good idea are the sort of people who thi…

The EU HASN'T delegated everything to local regulators. Have you not come across the Article 29 Working Party, which is dedicated to standardising GDPR interpretations across the EU?

Yes, here's the latest guidance I'm referring to:

https://ec.europa.eu/commission/sites/beta-political/files/d...

The successor of the working party is a new body called the "European Data Protection Board" (or sometimes supervisor). It will issue binding decisions but only on the matter of cross-border transfer disputes, not any other aspect of the new rules:

> The European Data Protection Board will not only issue guidelines on how to interpret core concepts of the Regulation but will also be called on to issue binding decisions on disputes regarding cross-border processing.

So the EU will issue "guidance", but so will local regulators, however, it's ultimately the EU itself via the ECJ that decides what the law actually means in the end:

> It is important to recall that, where questions regarding the interpretation and application of the Regulation arise, it will be for courts at national and EU level to provide the final interpretation of the Regulation

That is, if the EDPB or a local regulator states that something is legal, that doesn't stop them later taking you to court over it and winning because ultimately their own advice is not legally binding (except, perhaps, in the cross-border case which is a special exception for some reason).

> The data protection authorities are the natural interlocutors and first point of contact for the general public, businesses and public administrations for questions regarding the Regulation. The data protection authorities' role includes informing controllers and processors of their obligations and raising the general public’s awareness and understanding of the risks, rules, safeguards and rights in relation to data processing.

In other words local regulators are now essentially advocacy organisations that will be the first point of contact, but have no special powers to actually specify what is or is not allowed.

Re: GDPR: Don't Panic

#362
post #59

I can't help but love the turmoil GDPR is causing in the adtech "industry". Like wasps buzzing around the exterminator who's about to destroy their nest.

When people losing their jobs due to government overreach makes you happy, check your motivations.

LOL!

I'll shed many tears for those poor people whose only fault was that they've built a business on unsolicited collection of personal data :'(

Re: GDPR: Don't Panic

#363

Earlier quoted context omitted.

The only thing I can do as a customer is be mildly amused at the fact that you're complaining it's inconvenient for you to respect my privacy now that a law is coming into effect forcing you to do so. From the other end of the spectrum, I know you're wildly exaggerating the difficulty of compliance.

It's not inconvenient, it's costing me money . I don't want your data, I need to collect it and store it to comply with other laws, now I need to verify that the particular way I collect and store that data isn't violating some other new law. You are not my customer , but even if you were, keep in mind that for every piece of regulation (and there's tons of it!) I need to fulfill, I have to pay, which means you need…

If you need to have data to comply with other laws, the GDPR does not apply and thus there is no problem.

Re: GDPR: Don't Panic

#364

Earlier quoted context omitted.

The law says that the fines should be "effective, proportionate and dissuasive". That gives companies ample room to challenge a fine that is way out of proportion to the damages caused to their users.

You say this as though "challenging a fine" were trivial. After countless months spent in a courtroom and tens of thousands of Euros in legal fees, even if you win, you lose.

If you are fined 10k-100k you have the typical problem of whether it is worth fighting..

But you are supporting the argument that you could be illegally (according to article 83) fined 4 million euros as a first offence because a regulator wants to be disproportionate and set an example with your small company and then have costs of 10-100k to throw out an obvious case, but it wouldn't be worth it?

Re: GDPR: Don't Panic

#365
I don't think it's really that simple. especially the deletion requirements. There are just so many IT systems that really don't support deletion. An absolute worst case I can imagine is GitHub being asked to delete an account which had commits in multiple large projects. Are they going to alter those projects source code?

Re: GDPR: Don't Panic

#366

Earlier quoted context omitted.

That is absurd and wrong. The law says the fine needs to be proportionate: GDPR 83.1: Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this Article in respect of infringements of this Regulation referred to in paragraphs 4, 5 and 6 shall in each individual case be effective, proportionate and dissuasive.

Proportionate is in the eye of the beholder. As I stated in another response, an example might be that a low-level offense receives a fine of only 10% of the maximum - just $2 million. And apparently I don't need to worry, because I can just spend six figures hiring an attorney in a country I've never been to, who possibly speaks a language I don't, who will fight the case for me if the fine is out of line. Sounds ve…

> who possibly speaks a language I don't

I'm assuming you speak English. Do you really think there's any lawyer in the EU, competent to litigate EU law, who doesn't speak near-fluent English?

(Actually, if the lawyer is from continental Europe, and you only speak English, they do speak at least one language you don't, but I'm guessing that's not what you meant.)

Re: GDPR: Don't Panic

#367

For those of you understandably intimidated by the GDPR regulations themselves, here's a good summary in plain English: https://blog.varonis.com/gdpr-requirements-list-in-plain-eng... The UK's ICO also has a good structured summary: https://ico.org.uk/for-organisations/guide-to-the-general-da... In general I agree with the sentiments in this article. I've probably spent a total of three to four days reading around th…

There is nothing - and I do mean nothing - written into the GDPR that requires any warnings of any kind, or places any limits on fines, except for $10/$20 million or 4% of revenue, whichever is greater. Period. A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR. The idea that "yes it says that but we can trust EU regulators to not assess large fines against foreign…

> If you have a broad distrust of any government activity then I suppose any new laws with "fines up to €X" might feel like "I run a small site on a Digital Ocean droplet and I'm at risk of a €2m fine out of the blue." But that doesn't make it true.

Re: GDPR: Don't Panic

#368

Earlier quoted context omitted.

You're right, laws in Europe are uncivilized, maybe that's why they have the highest rate of incarceration in the world.

GDPR is extremely uncivilized. Forgetting the absurd fines and burdens it places on companies for a moment, consider the extraterritorial reach that EU is claiming for itself. The EU has declared itself Grand Emperor of the Internet. Wars have been fought over less.

Many countries believe their law applies extraterritorially. The US Foreign Corrupt Practices Act applies to any company that does any business in the US. A German director of a Canadian company that pays a bribe to an Ethiopian government official can be prosecuted under the FCPA if they set foot in the US. Sweden will prosecute citizens, and I presume residents, who purchase the services of a sex worker abroad. I don’t believe Kim Dotcom ever set foot in the US before the New Zealand government arrested him on foot of a US extradition warrant.

Re: GDPR: Don't Panic

#369

For those of you understandably intimidated by the GDPR regulations themselves, here's a good summary in plain English: https://blog.varonis.com/gdpr-requirements-list-in-plain-eng... The UK's ICO also has a good structured summary: https://ico.org.uk/for-organisations/guide-to-the-general-da... In general I agree with the sentiments in this article. I've probably spent a total of three to four days reading around th…

The amount of discretion and lack of clarity in the penalties is part of the problem. It opens you up to risk based on the whims of politics and the regulators and increases uncertainty. Laws should be clear, limited, and understandable - this is not.

> based on the whims of politics and the regulators

Political whims? Maybe in the USA judges and prosecutors and police cheifs are elected every few years and these things are political and can change, but this isn't the case in many EU countries.

Re: GDPR: Don't Panic

#370

Earlier quoted context omitted.

>Maximum possible fine for repeated worst possible violation after ignoring previous attempts at regulation and not making changes after previous smaller fines. Nothing in the GDPR states this. It's obviously the intent , but ultimately it's left up to the bon vouloir of EU regulators. It is perfectly legal under the GDPR to make an example out of you by levying the maximum fine for a first offense, and without warni…

>It is perfectly legal under the GDPR to make an example out of you by levying the maximum fine for a first offense, and without warning. No it isn't. Read Article 83. https://gdpr-info.eu/art-83-gdpr/

Neither Article 83 or 29 impose any actual limits. They say that those imposing fines should take some things into consideration. After which they can impose a multimillion-dollar fine.
Post reply on HN