Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

41–50 of 833 posts

Re: GDPR: Don't Panic

#41
The GDPR gets so much hate because it hits so many businesses where it hurts: data. GDPR "simply" gives you guidelines on how you can handle data from people within the EU. And that that data cannot be handled so liberally as it has been before. Of course that's annoying from a business perspective, but from an individuals privacy perspective, it's fantastic.

Re: GDPR: Don't Panic

#42

Earlier quoted context omitted.

It is easy if they believe particular person's interpretation. But that doesn't mean they are right. People have huge problems with interpreting written word if it is not written without a room for interpretation and if you add to the mix bureaucrats that have targets to meet you'll see it will not be easy at all.

Am in EU, am involved in some compliance stuff and have talked to plenty others at other companies, and it really does seem to be a nothing-to-see-here for all companies except the sleezy ones.

In all of my research, talking to lawyers, and seminars on GDPR, it is about:

1. Ask permission for collecting data

2. Keep sensitive data safe

3. Restrict access to said data

4. Keep a log of what happens with the data

5. Delete it upon request

6. Have all of the above documented and adhere to the protocol.

It's such a none issue unless you're relying on the very thing GDPR is designed to combat. If you not collecting and selling peoples data, and you don't do the above already, see this as a good opportunity to do what you should have been doing all along. There is such an awareness now, that it's the easiest it has ever been to know how to handle sensitive data properly.

Re: GDPR: Don't Panic

#44
post #32

Here in UK I have been receiving about 5-10 emails a day from various companies - most of whom I don't remember - telling me I need to sign up again so they can keep my details and keep spamming me. Fantastic.

I'm loving that too. It's amazing just how many mailing lists I'm on that I either haven't signed up for myself or have forgotten about.

Indeed. I was reading a tragic article about the energy cost of bitcoin and I started to wonder how much energy, bandwidth,HD space is totally wasted on sending everybody spam, junk, messages every day that they will never read. And keeping info for the same. I wonder if it is a reasonably large chunk of the total energy and infrastructure of the whole web?

Maybe we could power a big Chinese city just by getting ourselves deleted from gym mailing lists (weirdly a gym in Cardiff sends me spam mail -- I have never been to Cardiff???).

Re: GDPR: Don't Panic

#45

Earlier quoted context omitted.

It is easy if they believe particular person's interpretation. But that doesn't mean they are right. People have huge problems with interpreting written word if it is not written without a room for interpretation and if you add to the mix bureaucrats that have targets to meet you'll see it will not be easy at all.

Am in EU, am involved in some compliance stuff and have talked to plenty others at other companies, and it really does seem to be a nothing-to-see-here for all companies except the sleezy ones.

Is there even a single thing forbidden under GDPR that wasn't already forbidden before in at least half a dozen member states? In that case, it makes everything easier except for ignoring requirements.

Re: GDPR: Don't Panic

#46

Earlier quoted context omitted.

On what experiences with EU bureaucracy do you base your statement?

on what experience about gdpr case law is the linked article basing his statement? all those claims about warning shots and leniency and goodwill of the regulator are completely unfounded. the linked article makes the claim, the linked article should substantiate the claims, and we maintain a healthy right to remain skeptical of those claims until some meat is added to them.

The national regulators have been operating the previous regime for twenty years, so there IS plenty of experience and history to look at. The UK's ICO has made quite clear that the style will not change, as have bodies in other countries.

Re: GDPR: Don't Panic

#47

I was hoping for a nice respite to the anti-GDPR stuff we've seen recently, but this is just naked propaganda. In particular, the sentence: "the GDPR has the potential to escalate to those levels but in the spirit of the good natured enforcers ..." The author seems to have the idea that bureaucratic EU systems are inherently "good" and that even if things look bad on paper, it will be fine because they are "good" peo…

Do you have any experience with a Eu country internet regulatory service? I have experience with the CNIL (The french one), and they were helpfull and yes, good-natured. Part of our demand to be able to host data from hospital was drafted with their help, when they had no legal obligation to help us. A friend who work in a legal/tech startup also had good experience with them, and i don't know anybody who ever had a bad run with them. So if you have contradictory experience, please share them. Until then, i'll still take all this "GDPR will kill tech companies" articles from people who only experienced the US legal system as jokes.

Re: GDPR: Don't Panic

#48
This doesn't consider some factors that dictate how strong any company will experience their firehose of GDPR requests to be:

- how incentivised people are to make GDPR subject access requests of the company (how angry, confused, hostile curious they are)

- how easy it is for them to make requests (entirely manual vs. online service)

- wildcard factors (internet flash mobs bent on vengeance against a corporate)

There are also possible business models that might incentivize technology players to deliberately ramp up GDPR requests.

For example, unsuccessful candidates applying for a job at a company could forward their rejection email to a bot. The bot parses the details and fires a GDPR access request in to the HR department. The candidate gets back a formatted dump by email of all sorts of recruitment data, including interview notes, etc. There are obvious ways to monetise a service like this, hence incentive for someone to do it. Recruitment at a large company means engaging with thousands of people and then rejecting them. It is natural for people to have bruised feelings, and also to be curious about why they were not hired. A GDPR button lets them indulge their curiousity and start digging in to interview notes etc.

Naturally GDPR requests like this won't flood a company on the first day of GDPR. But the internet is a turbulent place.

Re: GDPR: Don't Panic

#49
post #37

The problem of multiple ambiguities in GDPR hasn't really been addressed here. Also, must be nice to live in a country where the regulator is as benevolent and reasonable as is described in this article. I think it's ok for foreigners to be skeptical of this promise, as the article implies that this reasonableness is not encoded in law.

The regulators have been running for two decades, and this is EXACTLY how they operate. Scepticism in this case is unreasonable, given the massive evidence base.

Re: GDPR: Don't Panic

#50
For those of you understandably intimidated by the GDPR regulations themselves, here's a good summary in plain English: https://blog.varonis.com/gdpr-requirements-list-in-plain-eng...

The UK's ICO also has a good structured summary: https://ico.org.uk/for-organisations/guide-to-the-general-da...

In general I agree with the sentiments in this article. I've probably spent a total of three to four days reading around the GDPR and I don't really see what's special about this law other than it's imposing decent standards on what was in effect a wildly unregulated industry in people's personal data. If you have a broad distrust of any government activity then I suppose any new laws with "fines up to €X" might feel like "I run a small site on a Digital Ocean droplet and I'm at risk of a €2m fine out of the blue." But that doesn't make it true.

Post reply on HN