Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

411–420 of 833 posts

Re: GDPR: Don't Panic

#411

Earlier quoted context omitted.

You're right, laws in Europe are uncivilized, maybe that's why they have the highest rate of incarceration in the world.

GDPR is extremely uncivilized. Forgetting the absurd fines and burdens it places on companies for a moment, consider the extraterritorial reach that EU is claiming for itself. The EU has declared itself Grand Emperor of the Internet. Wars have been fought over less.

I think you've got it backwards. GDPR is bringing civility back. I think it's great legislation that favors peoples privacy over business profits made by invading that privacy. As a business owner myself, I'm glad something like GDPR came along. I think it better reflects the society I want to live in.

Re: GDPR: Don't Panic

#412

Earlier quoted context omitted.

It takes time, and real money to be compliant, and getting slow on this quite plausibly can make one a repeat offender. You can, of course, say "don't be slow then", however, when for an out-of-EU entity (be it biz, or NGO) simple math doesn't show it is worth the effort, then it makes perfect sense to stop offering services to EU. Which is a side effect of the legislation. OP apparently understands it puts GDPR in a…

> It takes time, and real money to be compliant, and getting slow on this quite plausibly can make one a repeat offender. When I read things like this I realize how many companies are not treating user data as they should. Protecting user data should already be built into the company software and process. Given FB revelations and additional scrutiny to Google, I see some form of this law coming to the US.

Yes. We've had PECR for years. If companies are surprised by GDPR they're probably already violating PECR.

But, dispite this widespread non-compliance and fierce fines available to the regulators the sky hasn't fallen. Why do people think GDPR is sudden;y going to make things so much worse?

Re: GDPR: Don't Panic

#413
post #377

Earlier quoted context omitted.

I am concerned that the effect of this legislation on the private individual is the opposite of the stated intention. People are being forced to sign agreements which jeopardise the natural rights to their data which they would otherwise have. One example: a friend who has a very pretty daughter was asked by her school to give them the right to film her and to use any and all such recordings as they see fit for 50 ye…

Under the GDPR, consent must be revokable, at any time, and as easy to withdraw consent as to give it. So you could sign that. Then 5 minutes later withdraw consent. Additionally consent must be "freely given". If you would be punished (e.g. expelled from school) then you haven't given consent, so they can't use it.

"freely given" is not a very clear concept in these circumstances. Parents do not want to antagonise the school and/or put their child at some kind of disadvantage, so they sign. Is that still "freely given"? It looks like GDPR is being used (as an excuse?) to make parents sign things which otherwise they might not. I hear you say that that is not the problem of GDPR and you can withdraw your consent later but how many will know that or remember to do so?

From the above "school might have to reprint all its publicity materials if consent is withdrawn" it is clear that this would be viewed as being antagonistic towards the school and its interests.

Re: GDPR: Don't Panic

#414
post #364

Earlier quoted context omitted.

You say this as though "challenging a fine" were trivial. After countless months spent in a courtroom and tens of thousands of Euros in legal fees, even if you win, you lose.

If you are fined 10k-100k you have the typical problem of whether it is worth fighting.. But you are supporting the argument that you could be illegally (according to article 83) fined 4 million euros as a first offence because a regulator wants to be disproportionate and set an example with your small company and then have costs of 10-100k to throw out an obvious case, but it wouldn't be worth it?

It's worth it but it bankrupts you.

No customers, no investors, and all your cash gone before your appeal is heard.

Block all EU traffic. Just cut the transatlantic cables.

Re: GDPR: Don't Panic

#415
As an European (Finnish), Fuck The GDPR. It is literal cancer.

It is a stepping stone to arbitrary enforcement laws: "Trust us, we do no harm".

This is not how laws should be written. This goes 100% against anything that is fair in this world. Either you write laws that apply (and are enforced) the same to everyone or you just fucking don't.

If you can't do that you shouldn't be writing laws that affect milliards of people.

Re: GDPR: Don't Panic

#416

Earlier quoted context omitted.

That's what we've chosen to do. The reality is that most businesses outside the EU will wind up blocking EU traffic, simply because they don't want the liability.

Same here. EU makes up such a small amount of or customer base, and EU customers spend far less money with us. Which is generally true in most industries, US consumers spend far more than consumers anywhere else in the world. If we ever choose to enter the EU again, it will be a careful and deliberate choice, and will likely only ever happen if our growth slows in other regions.

As a formerly European person running internet companies in the USA this baffles me. Why the teeth gnashing over being told not to spy on your users?

Re: GDPR: Don't Panic

#417

Earlier quoted context omitted.

Or, you know, just block European clients from your service if you don't agree to our laws? It's not like if the US laws didn't have any extraterritoriality.

It's not like if the US laws didn't have any extraterritoriality. This is a disingenuous argument. The US has never passed a law that is this easy to violate outside of its own borders, is this ripe for abuse, and carries such enormous penalties and burdens for essentially everyone in the world that wants to operate a website. In fact, no country has ever done this before. GDPR is different, and not in a good way.

> The US has never passed a law that is this easy to violate outside of its own borders

The US has a law requiring US citizens living and working outside of the US to file taxes in the US. Not doing that is a crime. You'll probably argue that this is different, since it concerns American citizens, but it isn't different, because it's a US law that is very easy to violate outside of its borders.

Re: GDPR: Don't Panic

#418
post #358

Earlier quoted context omitted.

There is nothing - and I do mean nothing - written into the GDPR that requires any warnings of any kind, or places any limits on fines, except for $10/$20 million or 4% of revenue, whichever is greater. Period. A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR. The idea that "yes it says that but we can trust EU regulators to not assess large fines against foreign…

> A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR Come on, this is just scaremongering. Newsflash: If you run a business, you are already responsible for adhering to hundreds of other laws in which the fines could reach millions. But you don't see people running around screaming that the world is ending, because they know that the laws will generally be applied f…

I have a feeling there are a significant number of people who are young enough to have only worked in digital media, and who aren't used to the idea that businesses are regulated. It's been such a free-for-all until now that they're not used to the idea that there might be externally-imposed limitations on what they can do. I don't mean that in a dismissive way - nobody willingly reads complex legislation in industries that they're not involved in - but it would explain some of the more naive complaints.

Re: GDPR: Don't Panic

#419

Earlier quoted context omitted.

>It is perfectly legal under the GDPR to make an example out of you by levying the maximum fine for a first offense, and without warning. No it isn't. Read Article 83. https://gdpr-info.eu/art-83-gdpr/

Neither Article 83 or 29 impose any actual limits. They say that those imposing fines should take some things into consideration. After which they can impose a multimillion-dollar fine.

Kinda common in continental European law... Nothing new, nothing to be scared of.

Re: GDPR: Don't Panic

#420

Earlier quoted context omitted.

Or, you know, just block European clients from your service if you don't agree to our laws? It's not like if the US laws didn't have any extraterritoriality.

It's not like if the US laws didn't have any extraterritoriality. This is a disingenuous argument. The US has never passed a law that is this easy to violate outside of its own borders, is this ripe for abuse, and carries such enormous penalties and burdens for essentially everyone in the world that wants to operate a website. In fact, no country has ever done this before. GDPR is different, and not in a good way.

Lol, the US has FATCA which makes it very difficult for fin-tech startups to work with americans. I'm an e-resident of Estonia, and almost all financial services state they cannot serve US clients.
Post reply on HN