Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

371–380 of 833 posts

Re: GDPR: Don't Panic

#371

I don't think it's really that simple. especially the deletion requirements. There are just so many IT systems that really don't support deletion. An absolute worst case I can imagine is GitHub being asked to delete an account which had commits in multiple large projects. Are they going to alter those projects source code?

This is already a “solved problem” though. If you post copyrighted material to Github, Github will have to remove it.

If you’re posting users information to a public repo, then you fully deserve whatever impacts you’ll face when you have to delete it.

Re: GDPR: Don't Panic

#372

Earlier quoted context omitted.

There is nothing - and I do mean nothing - written into the GDPR that requires any warnings of any kind, or places any limits on fines, except for $10/$20 million or 4% of revenue, whichever is greater. Period. A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR. The idea that "yes it says that but we can trust EU regulators to not assess large fines against foreign…

I think you and everyone making similar points in this thread are getting tripped up by the difference between rules-based regulation and principles-based regulation. This is unsurprising, given that the US is so heavily rules-based, but the EU (certainly the UK) has a long history of principles-based regulation. In rules-based regulation, all the rules are spelled out in advance, and the regulator is basically an au…

>and you'll have to engage with it on those terms

Or you can just disengage with Europe all together, which is an obvious choice for many small to medium sized companies, given the risks and costs involved.

Re: GDPR: Don't Panic

#373
post #114

Earlier quoted context omitted.

As mentioned elsewhere, these regulators have been operating for a very long time. Even when dealing with the whole Facebook / Cambridge Analytica they're moving quite slowly. There have been various legal changes regarding privacy in the past. E.g. for The Netherlands it is not allowed to have a checkbox on by default to sign up to a mailing list. There's a fine if you don't abide and this fine can be very hefty. In…

The substance of this line of criticism is that yes, it's probably going to be fine. But if it's not, they can fine you at 4% of global turnover. They probably won't, but they literally can . "I read on a blog that they'd be nice and send me a warning first" gets you exactly nowhere in court ("very well, but what did your lawyer tell you?"). The article praises the GDPR for having teeth -- being timid can be somethin…

> "I read on a blog that they'd be nice and send me a warning first"

That's not what happened. Various people pointed out various cases where it's shown over the course of 20 years what happened. Ample history.

> Don't panic, but take the advice of a non-lawyer's blog over your actual lawyer's at your own extreme peril.

Are you from the US or EU? Immediately going to a lawyer seems strange and unique to me. Within a big company, yeah, lawyer. Anything else unless you're doing something specific I don't see why.

Re: GDPR: Don't Panic

#374

Earlier quoted context omitted.

I think you and everyone making similar points in this thread are getting tripped up by the difference between rules-based regulation and principles-based regulation. This is unsurprising, given that the US is so heavily rules-based, but the EU (certainly the UK) has a long history of principles-based regulation. In rules-based regulation, all the rules are spelled out in advance, and the regulator is basically an au…

>and you'll have to engage with it on those terms Or you can just disengage with Europe all together, which is an obvious choice for many small to medium sized companies, given the risks and costs involved.

That's what we've chosen to do. The reality is that most businesses outside the EU will wind up blocking EU traffic, simply because they don't want the liability.

Re: GDPR: Don't Panic

#375
post #120

Earlier quoted context omitted.

It is highly unlikely that a lot of requests will "sink" your company. As per the GDPR, you have a month to respond to requests and you can extend this period by two more months by telling the user that you need more time to process their request. (See article 12 for reference)

If 10% of the members of my website request a GDPR, then my website will no longer exist. The processing time for that would be a decade.

What does it mean to "request a GDPR"?

Re: GDPR: Don't Panic

#376

Earlier quoted context omitted.

There is nothing - and I do mean nothing - written into the GDPR that requires any warnings of any kind, or places any limits on fines, except for $10/$20 million or 4% of revenue, whichever is greater. Period. A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR. The idea that "yes it says that but we can trust EU regulators to not assess large fines against foreign…

In England and Wales, you could be fined £10^99 for having a crumb of cannabis in your pocket. There is nothing - and I do mean nothing - written in the Misuse of Drugs Act that requires any warnings of any kind, or places any limits on fines. The maximum sentence for possession of a Class B controlled substance is five years imprisonment and an unlimited fine. Period. A fine larger than the number of atoms in the un…

> In England and Wales, you could be fined £10^99 for having a crumb of cannabis in your pocket. There is nothing - and I do mean nothing - written in the Misuse of Drugs Act

Not true.

https://www.legislation.gov.uk/ukpga/1971/38/section/25

> The fourth, fifth and sixth columns show respectively the punishments which may be imposed on a person convicted of the offence in the way specified in relation thereto in the third column (that is to say, summarily or on indictment) according to whether the controlled drug in relation to which the offence was committed was a Class A drug, a Class B drug or a Class C drug; and

https://www.legislation.gov.uk/ukpga/1971/38/schedule/4

Cannabis is currently class B, thus

> [F8 3 months or [F4 £2,500], or both].

Re: GDPR: Don't Panic

#377

For those of you understandably intimidated by the GDPR regulations themselves, here's a good summary in plain English: https://blog.varonis.com/gdpr-requirements-list-in-plain-eng... The UK's ICO also has a good structured summary: https://ico.org.uk/for-organisations/guide-to-the-general-da... In general I agree with the sentiments in this article. I've probably spent a total of three to four days reading around th…

I am concerned that the effect of this legislation on the private individual is the opposite of the stated intention. People are being forced to sign agreements which jeopardise the natural rights to their data which they would otherwise have. One example: a friend who has a very pretty daughter was asked by her school to give them the right to film her and to use any and all such recordings as they see fit for 50 ye…

Under the GDPR, consent must be revokable, at any time, and as easy to withdraw consent as to give it. So you could sign that. Then 5 minutes later withdraw consent.

Additionally consent must be "freely given". If you would be punished (e.g. expelled from school) then you haven't given consent, so they can't use it.

Re: GDPR: Don't Panic

#378
post #185

Earlier quoted context omitted.

What ? It's the opposite, it allow you to access and delete the data, even if you gave consent one time. And your image concern a lot of other old laws, even if you sell it you can get it back later.

I have difficulty in understanding your language and in following your logic. Surely, signing away the rights to your records for over 50 years can not be better for you than not signing them?

Under the GPDR, you can't "sign away" your rights. You always have the right to cancel any "contract"/"agreement" like that.

Re: GDPR: Don't Panic

#379

Earlier quoted context omitted.

You're right, laws in Europe are uncivilized, maybe that's why they have the highest rate of incarceration in the world.

GDPR is extremely uncivilized. Forgetting the absurd fines and burdens it places on companies for a moment, consider the extraterritorial reach that EU is claiming for itself. The EU has declared itself Grand Emperor of the Internet. Wars have been fought over less.

Or, you know, just block European clients from your service if you don't agree to our laws?

It's not like if the US laws didn't have any extraterritoriality.

Re: GDPR: Don't Panic

#380

Earlier quoted context omitted.

You're right, laws in Europe are uncivilized, maybe that's why they have the highest rate of incarceration in the world.

GDPR is extremely uncivilized. Forgetting the absurd fines and burdens it places on companies for a moment, consider the extraterritorial reach that EU is claiming for itself. The EU has declared itself Grand Emperor of the Internet. Wars have been fought over less.

You make it sound like US laws don't extend outside the US. Many of them do.
Post reply on HN