Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

391–400 of 833 posts

Re: GDPR: Don't Panic

#391

Earlier quoted context omitted.

That is absurd and wrong. The law says the fine needs to be proportionate: GDPR 83.1: Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this Article in respect of infringements of this Regulation referred to in paragraphs 4, 5 and 6 shall in each individual case be effective, proportionate and dissuasive.

Proportionate is in the eye of the beholder. As I stated in another response, an example might be that a low-level offense receives a fine of only 10% of the maximum - just $2 million. And apparently I don't need to worry, because I can just spend six figures hiring an attorney in a country I've never been to, who possibly speaks a language I don't, who will fight the case for me if the fine is out of line. Sounds ve…

The mandate of the regulator is to create compliance. Of course any institution can randomly decide to act outside of their mandate. If they would start to do so, the courts would rule them in. Same as anything. Doing business in the US, with it's notion of punitive damages that are completely unconstrained by law is a much larger risk.

On that token, have you actually at all looked into how "proportionate" is interpreted legally? After all this isn't new and there are a vast number of regulations using the same legal language. Yet somehow business in Europe has not stopped. So prima facie your concerns are absurd, you have not brought evidence that there is an issue (or anything at all unprecedented really) and I have to wonder what motivates you.

As others have said, if you have no interest in complying with laws that protect my privacy, then it's appropriate for you to not do business here.

Re: GDPR: Don't Panic

#392
post #387

It ain't hysteria if you're in Germany, and a private individual or a nonprofit (e.V.). Due to specialities of German law third parties can serve you legal writs for hundreds or thousands of EURos. Which is why I'm shutting down these 20 domains running HTTP/SMTP services I'm hosting in less than a week, and wait until the smoke clears.

GDPR doesn't apply to personal projects unless those are commercial projects.

Re: GDPR: Don't Panic

#393

Earlier quoted context omitted.

GDPR is extremely uncivilized. Forgetting the absurd fines and burdens it places on companies for a moment, consider the extraterritorial reach that EU is claiming for itself. The EU has declared itself Grand Emperor of the Internet. Wars have been fought over less.

Or, you know, just block European clients from your service if you don't agree to our laws? It's not like if the US laws didn't have any extraterritoriality.

It's not like if the US laws didn't have any extraterritoriality.

This is a disingenuous argument. The US has never passed a law that is this easy to violate outside of its own borders, is this ripe for abuse, and carries such enormous penalties and burdens for essentially everyone in the world that wants to operate a website. In fact, no country has ever done this before.

GDPR is different, and not in a good way.

Re: GDPR: Don't Panic

#394
post #58

Earlier quoted context omitted.

I guess we should only enact new laws which already have established case law. /s

> "I guess we should only enact new laws which already have established case law. /s" I disagree with the author's lenient and dismissive take on people's genuine concerns. Interpret it as you will.

That's fair. I do have my doubts about how genuine some of these concerns are though.

Re: GDPR: Don't Panic

#395

Earlier quoted context omitted.

> you also need a privacy policy if you are receiving phone calls. did you know that? You mean your website needs to have a note next to your phone number saying something like "we will not record your phone calls", and if there isn't, you're liable to be fined?

that or a mention directly at the start of the conversation.

An explicit mention that you will not record?

Re: GDPR: Don't Panic

#396

Earlier quoted context omitted.

You're right, laws in Europe are uncivilized, maybe that's why they have the highest rate of incarceration in the world.

GDPR is extremely uncivilized. Forgetting the absurd fines and burdens it places on companies for a moment, consider the extraterritorial reach that EU is claiming for itself. The EU has declared itself Grand Emperor of the Internet. Wars have been fought over less.

https://en.wikipedia.org/wiki/United_States_v._Elcom_Ltd. ?

The guy committed an "US crime" in Russia, where what he did was not illegal. He arrived on US soil, where he committed no crime.

He was still arrested and charged.

Re: GDPR: Don't Panic

#397

Earlier quoted context omitted.

There is nothing - and I do mean nothing - written into the GDPR that requires any warnings of any kind, or places any limits on fines, except for $10/$20 million or 4% of revenue, whichever is greater. Period. A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR. The idea that "yes it says that but we can trust EU regulators to not assess large fines against foreign…

I think you and everyone making similar points in this thread are getting tripped up by the difference between rules-based regulation and principles-based regulation. This is unsurprising, given that the US is so heavily rules-based, but the EU (certainly the UK) has a long history of principles-based regulation. In rules-based regulation, all the rules are spelled out in advance, and the regulator is basically an au…

Great explanation. I didn’t know the difference between US and U.K. law was so fundamentally different. Thank you for educating me on the correct terms.

Re: GDPR: Don't Panic

#398

Earlier quoted context omitted.

Or, you know, just block European clients from your service if you don't agree to our laws? It's not like if the US laws didn't have any extraterritoriality.

It's not like if the US laws didn't have any extraterritoriality. This is a disingenuous argument. The US has never passed a law that is this easy to violate outside of its own borders, is this ripe for abuse, and carries such enormous penalties and burdens for essentially everyone in the world that wants to operate a website. In fact, no country has ever done this before. GDPR is different, and not in a good way.

https://en.wikipedia.org/wiki/Digital_Millennium_Copyright_A...

https://en.wikipedia.org/wiki/United_States_v._Elcom_Ltd.

Re: GDPR: Don't Panic

#399

Earlier quoted context omitted.

There is nothing - and I do mean nothing - written into the GDPR that requires any warnings of any kind, or places any limits on fines, except for $10/$20 million or 4% of revenue, whichever is greater. Period. A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR. The idea that "yes it says that but we can trust EU regulators to not assess large fines against foreign…

I think you and everyone making similar points in this thread are getting tripped up by the difference between rules-based regulation and principles-based regulation. This is unsurprising, given that the US is so heavily rules-based, but the EU (certainly the UK) has a long history of principles-based regulation. In rules-based regulation, all the rules are spelled out in advance, and the regulator is basically an au…

> This is unsurprising, given that the US is so heavily rules-based, but the EU (certainly the UK) has a long history of principles-based regulation.

This is a good point, but many people seem to forget that most misdemeanor criminal offenses in the US are punishable by fine and/or up to 30+ days in jail. People do not often get the jail time so most don't even think about it, but it is available as an option to the judge for things like repeat offenders.

Re: GDPR: Don't Panic

#400
post #356

Earlier quoted context omitted.

It's like people are only now discovering that they are in fact living in a well structured society.......

There's a lot of American libertarians that believe government is intrinsically bad, for some reason. And also a monolith; they don't see any difference between bits of government, different branches, different types of enforcement, and so on. They're very loath to admit that it takes a certain minimum amount of structure to keep the roads open and the lights on.

> to keep the roads open and the lights on

I'd cynically add:

> and to prevent people from killing and robbing each other each day

There's a reason we have Wikipedia articles like this one:

https://en.wikipedia.org/wiki/Highwayman

Post reply on HN