Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

421–430 of 833 posts

Re: GDPR: Don't Panic

#421
post #396

Earlier quoted context omitted.

GDPR is extremely uncivilized. Forgetting the absurd fines and burdens it places on companies for a moment, consider the extraterritorial reach that EU is claiming for itself. The EU has declared itself Grand Emperor of the Internet. Wars have been fought over less.

https://en.wikipedia.org/wiki/United_States_v._Elcom_Ltd . ? The guy committed an "US crime" in Russia, where what he did was not illegal. He arrived on US soil, where he committed no crime. He was still arrested and charged.

That’s one guy in one case (that was eventually dismissed). There are probably a few handfuls of other examples you can post here. It doesn't hold a candle to the millions of people and businesses liable under the GDPR who face a nasty framework of foreign laws with no limits on fines other than $10/20 million.

Re: GDPR: Don't Panic

#422
post #189

There's certainly no need to panic. The article doesn't address that apart from mindless hysteria there are some very real issues with GDPR. It doesn't have to of course because as the title suggests it's more about dispelling panic than about giving concrete advice. However, many real-life problems seemingly haven't even been considered by legislative bodies. In GDPR support forums questions like these have been rou…

Run your small company website without gathering personal data? No-one can sue you now, that couldn't before. I'm baffled that so many people believe this. I could complain about you to my country's regulation body. Then they could decide to audit you, and for a first offense issue a warning. If you need the address data for marketing only, and you didn't get an explicit (opt-in) yes to receive marketing, then sorry.…

I liked the aisle, but have a lot of issues with it. This is one of my main ones: IP addresses and information security. Quoting you:

> Storing an IP for a limited time for security reasons is fine. Have rules in place for how this data is used and when it is deleted. Don't keep it longer than nessescary.

How long is necessary? What does limited mean? Does a regulator now get to determine what sort of algorithms I can use to protect my assets? Advanced persistent threats (https://en.m.wikipedia.org/wiki/Advanced_persistent_threat) can exist over a very extended--and arbitrary time period! I'm in the security software industry, and we and our customers need to detect and react to these threats. That requires data which you simply cannot obtain an opt-in for. Sure, you put that in a posted privacy policy, but if you can only keep the data for 30 days, this means actual evidence of a crime might need to be thrown out.

Re: GDPR: Don't Panic

#423
post #376

Earlier quoted context omitted.

In England and Wales, you could be fined £10^99 for having a crumb of cannabis in your pocket. There is nothing - and I do mean nothing - written in the Misuse of Drugs Act that requires any warnings of any kind, or places any limits on fines. The maximum sentence for possession of a Class B controlled substance is five years imprisonment and an unlimited fine. Period. A fine larger than the number of atoms in the un…

> In England and Wales, you could be fined £10^99 for having a crumb of cannabis in your pocket. There is nothing - and I do mean nothing - written in the Misuse of Drugs Act Not true. https://www.legislation.gov.uk/ukpga/1971/38/section/25 > The fourth, fifth and sixth columns show respectively the punishments which may be imposed on a person convicted of the offence in the way specified in relation thereto in the t…

You've misread the legislation. The maximum sentences you're referring to are for summary convictions at a magistrates court. Possession of a controlled substance is an each-way offence which can be tried at either a magistrates or crown court. There is a higher maximum sentence if your offence is tried at a crown court, which is listed in schedule 4, namely "5 years or a fine, or both".

Re: GDPR: Don't Panic

#424
post #396

Earlier quoted context omitted.

https://en.wikipedia.org/wiki/United_States_v._Elcom_Ltd . ? The guy committed an "US crime" in Russia, where what he did was not illegal. He arrived on US soil, where he committed no crime. He was still arrested and charged.

That’s one guy in one case (that was eventually dismissed). There are probably a few handfuls of other examples you can post here. It doesn't hold a candle to the millions of people and businesses liable under the GDPR who face a nasty framework of foreign laws with no limits on fines other than $10/20 million.

Go read the law again. Read what the friendly people are answering in this whole sub-thread started by you.

Re: GDPR: Don't Panic

#425
post #145

Earlier quoted context omitted.

Maximum possible fine for repeated worst possible violation after ignoring previous attempts at regulation and not making changes after previous smaller fines. It's not a minimum.

It takes time, and real money to be compliant, and getting slow on this quite plausibly can make one a repeat offender. You can, of course, say "don't be slow then", however, when for an out-of-EU entity (be it biz, or NGO) simple math doesn't show it is worth the effort, then it makes perfect sense to stop offering services to EU. Which is a side effect of the legislation. OP apparently understands it puts GDPR in a…

The whole world has had TWO YEARS to be compliant. "It takes time" is not an excuse.

Re: GDPR: Don't Panic

#426

Earlier quoted context omitted.

Same here. EU makes up such a small amount of or customer base, and EU customers spend far less money with us. Which is generally true in most industries, US consumers spend far more than consumers anywhere else in the world. If we ever choose to enter the EU again, it will be a careful and deliberate choice, and will likely only ever happen if our growth slows in other regions.

As a formerly European person running internet companies in the USA this baffles me. Why the teeth gnashing over being told not to spy on your users?

GDPR and “not spying on your users” are not even remotely related. GDPR is a massive regulation requiring significant resources that most small businesses simply don’t have.

Re: GDPR: Don't Panic

#427

This article actually points out my philosophical problem with GDPR. In one point he says you have to be compliant if you want to do business in the EU. In another he observed that it is difficult (maybe impossible) to block EU folks from coming to a web presence. It’s the expansive reach that bugs me. I’ll note that for real businesses this is just a thought excercise, but it’s one I keep coming back to. What if som…

Are you American, by any chance? The whole internet dances to the US tune, legally.

Welcome to our world :)

Re: GDPR: Don't Panic

#428

Earlier quoted context omitted.

>and you'll have to engage with it on those terms Or you can just disengage with Europe all together, which is an obvious choice for many small to medium sized companies, given the risks and costs involved.

Good lord, it's like you didn't read the article. Or, you're fine with a competitor who isn't afraid of entirely reasonable international laws coming in and eating your lunch.

We ran the numbers on how much it would cost to establish compliance, and with that alone it was barley worth it based on the current EU customer base we have.

We also considered all the additional liability we’d be taking on, and with that alone it was barely worth it based on the current EU customer base we have.

We’d also be very happy if one of our competitors started investing in the EU market. It’s worth about 10 times less than the US market in our industry, so having them chasing peanuts in Europe (and investing in compliance with European - absolutely not international - regulations) would be a truely fantastic outcome for us.

Re: GDPR: Don't Panic

#429
post #2

How does this affect people who aren't based in Europe?

I think many (most?) companies will implement these privacy policies across all of their users as it can be hard to determine whether a user is in the EU or not... so indirectly, this law might mean that everybody will finally have strong privacy guarantees (at least when it comes to companies of a meaningful size).

> I think many (most?) companies will implement these privacy policies across all of their users

In terms of percentages, exceptionally few businesses outside of the EU will implement GDPR. The rest of the world will overwhelmingly entirely ignore it.

There are 20 million businesses in the US. 500,000 new businesses are created each year. 0.1% or less will comply with GDPR. Why? Because very few US businesses ever do business with the EU.

A small clothing retail shop from Texas or Florida or Michigan is not going to concern itself with complying with GDPR just because they took three orders from the EU. They're going to ignore GDPR and continue doing business as they always have. And the EU is going to find it entirely impossible to enforce compliance for those types of small instances due to the scale & tracking required to do so. If by chance they develop a larger EU business, then they'll comply.

Further, how do you force compliance on a US clothing shop from Florida, that sells 27 items per year into the EU, and violates GDPR (while having zero presence in the EU)? They can't, unless the EU develops a Chinese firewall.

The extremely majority of small businesses in India and China also do not do business with the EU. They will not be worried about GDPR. That's true about nearly all the rest of the businesses around the globe.

Re: GDPR: Don't Panic

#430

Does anybody know if it's required to remove CDN links (such for Google fonts, cdnjs, etc.) and host all assets locally instead unless consent is given? Assets from CDNs are required for a site to function; what's not required is to send `Referer:` so maybe it's sufficient to set a referrer-policy.

I wonder the same. Would I need the web visitor's consent for loading a reCaptcha to verify they're indeed human?

Google fonts is just one of the many font libraries. For example, most web font licenses at myfonts.com don't permit webmasters to self host them. Bypassing the HTTP referer download protection, downloading them and then self hosting the font files could lead to significant legal problems.

Post reply on HN