Live data from Hacker News

GDPR fines were meant to rock the data privacy world

wired.co.uk

41–50 of 99 posts

Re: GDPR fines were meant to rock the data privacy world

#41

Earlier quoted context omitted.

The article you're commenting on mentions reasonably large firms being held accountable. What's your basis for the "smallest and weakest" claims?

The GPDR is a large compliance burden. The bigger your company is the less this hurts you because it’s very approximately a fixed cost. So the GPDR kneecaps small companies while being a painful but bearable expense for large ones. On net it helps the internet giants by reducing competition.

Not what I would call a kneecapping, or even a burden.

Compliance cost at the place I work in the UK was negligible. We have personal data on every customer, had to make some one time code changes, and ongoing costs are essentially zero. Frankly, compliance was trivial and little different to Data Protection - which was also trivial to comply with.

If you're data mining everyone to death and selling it off to multiple unnamed third parties, compliance may well be more challenging. Hardly surprising as that's one of the things it's trying to constrain.

Re: GDPR fines were meant to rock the data privacy world

#42

Fun fact: in my country (Croatia), police officials cite GDPR as a reason they consider recording police officers in public illegal.

Fun fact: in east eu laws are bent to protect criminals, as they are essentially those in “power”. In Romania GDPR was used as means to threaten investigative journalists (see Rise Project and GDPR). There are other criminally bent laws that predate gdpr. For instance the government used some obscure privacy “concerns” mandated by the eu (not sure which) to remove ALL traffic monitoring cameras. The result is one of the highest road deaths in the EU and naturally easier to bribe traffic police. Organised crime members are also protected by bogus human rights interpretations, where a mobster gets more rights than and old lady stealing an egg for food.

Re: GDPR fines were meant to rock the data privacy world

#43

Earlier quoted context omitted.

The article you're commenting on mentions reasonably large firms being held accountable. What's your basis for the "smallest and weakest" claims?

Fines for larger companies are either too small to matter or will be negotiated down. Larger companies also have a much easier time gaining consent (like Google and Facebook) that clears their usage while smaller companies struggle. This can be seen by the constant consent popups on every website. Users click yes on the major sites, then deny the rest.

> Larger companies also have a much easier time gaining consent (like Google and Facebook) that clears their usage while smaller companies struggle.

I feel the opposite may be true. When the law came to pass, I took some time to review my privacy options on Google and Facebook, since they are a big impact for me.

On the other hand, when I click on a link on HN to some random news paper, and get presented with a five-step process to start to see my options, I don't usually bother and dismiss it as soon as I can, probably with some 'opt-in' consent. Since I'm not planning on viewing the site again, I consider it a minor annoyance.

Re: GDPR fines were meant to rock the data privacy world

#44
post #39
post #36

Has any web site been fined for not displaying the cookie notice?

Of course not. There is no law requiring cookie notice popups, there never was.

That's not true. It is law in the EU and companies have been fined:

https://www.cookielaw.org/blog/2014/2/5/spanish-cookie-law-f...

Re: GDPR fines were meant to rock the data privacy world

#46
It's the starting point we needed. Every time some company tries to get away with being unreasonable (see gitlab and ubiquiti from just last weeks) GDPR is one aspect that is quickly brought up. One they can not ignore as easily.

The privacy options we suddenly ot from large companies from companies such as facebook were unheard of before GDPR.

It have already drastically changed how the world handles data, but it is a slow process. It will take decades and more work.

Massive success all in all, thanks to GDPR there is now hope for the future.

Re: GDPR fines were meant to rock the data privacy world

#47
The effect that GDPR has as far as I'm concerned as a user is that many or even most sites accessed from EU come with a prominent banner warning about PII data collection for targetted ads, including a large portion of sites linked from HN. Maybe this isn't noticed on the other side of the pond, but it has a very profound effect on my usage, as I'm immediately turned away from such sites. OTOH, platform sites without ads such as github, where you supposedly already have agreed to their ToS, and where data isn't being used for ads (for the time being) don't suffer from this effect, yet.

Re: GDPR fines were meant to rock the data privacy world

#48

Fun fact: in my country (Croatia), police officials cite GDPR as a reason they consider recording police officers in public illegal.

The GDPR doesn't cover processing of personal data "by a natural person in the course of a purely personal or household activity". So I imagine that at least some instances of recording police officers in public are exempt, especially if you don't follow them around or upload the videos to your local police recordings online community. Of course I also wouldn't argue with the people with the batons.

Re: GDPR fines were meant to rock the data privacy world

#50
post #2

GDPR: A well-intentioned EU measure that unfortunately hurts the smallest and weakest and fails to have an impact on the big ones that it should target. Noble in thought, weak in action

How about some examples of the smallest and the weakest that have been hurt?
Post reply on HN