Live data from Hacker News

How GDPR Will Change The Way You Develop

smashingmagazine.com

441–450 of 710 posts

Re: How GDPR Will Change The Way You Develop

#441
post #406

Earlier quoted context omitted.

Good luck to EU trying to enforce it against JoeSchmoeLLC from PA

Not really a problem for EU if JoeSchmoeLLC is really treating this as not a law for them. US and pretty much every country in the EU have excellent extradition agreements. [0] [0] https://en.wikipedia.org/wiki/List_of_United_States_extradit...

Do you have any examples of the US extraditing anyone to Europe for actions not considered criminal in the United States.

Re: How GDPR Will Change The Way You Develop

#442
post #91

What's troubling to me is that it's very unclear what specifically is required. I know the linked post isn't legal advice, but in the page about 'privacy by design' linked to by the origin link, they list "Minimize the amount of collected data" as as an item (supposedly to be achieved to be in compliance with the law). What's the minimum amount of data? Who decides that? Is it dependent on context? I'd hope so! Can a…

> ...they list "Minimize the amount of collected data" as as an item (supposedly to be achieved to be in compliance with the law). > What's the minimum amount of data? Who decides that? Is it dependent on context? I'd hope so! The GDPR says when you collect data, you have to tell the user what you intend to use it for. "Minimization" applies within the context of those stated uses. So if your business purpose is to m…

> So if your business purpose is to mail something to the customer, full physical address is OK to collect. If your business purpose is to help them find a nearby store location, you may be expected to collect something less granular like ZIP code or metro area, depending on how many locations you have.

I would also like to stress out that, from my understanding, this data would rather be deleted immediately after use. That is, not saved at all after the query, or the delivery, unless the user explicitly opted-in to give you such data for advertising, etc...

Re: How GDPR Will Change The Way You Develop

#443
post #354

Earlier quoted context omitted.

> Every complaint about it shows that you don't respect others and you dont care about them. And this is the reason it became legislation. Ok, that is just silly. This sounds so much like the 'Why do you want privacy if you have nothing to hide?' arguments. It is very reasonable to both have a company that handle customer data responsibly AND have issues with the GDPR. Imagine if every time you walked down the street…

Oh, so in construction business, you don't need to prove your plans are statically safe, you just build a bridge and no one cares until it colapses? Don't worry, you are far safer here, no one will ask you anything until it collapses. But after it does, you will need a proof it didn't happen becoase of you. That you did all you could. Is there something wrong?

If my web app can kill you, sure we should add regulations that I have to follow and prove that I am following.

That is beside the point, though; I wasn't saying regulations were wrong, just that it is unfair to say "If you don't like this particular regulation than you don't care about customers"

That is wrong. You can disagree with how a regulation is implemented and still agree with the idea of having a regulation.

Re: How GDPR Will Change The Way You Develop

#444
post #403
post #354

Earlier quoted context omitted.

Oh, so in construction business, you don't need to prove your plans are statically safe, you just build a bridge and no one cares until it colapses? Don't worry, you are far safer here, no one will ask you anything until it collapses. But after it does, you will need a proof it didn't happen becoase of you. That you did all you could. Is there something wrong?

Indeed, capturing IP addresses in logs is exactly like a bridge collapsing and killing people.

I have lost 3 family members to logged IPs.

Re: How GDPR Will Change The Way You Develop

#445

Earlier quoted context omitted.

In principle, yes. The intention behind and the principles outlined by the GDPR are good. However, the devil's in the details, specifically in how these principles are supposed to be implemented. Some of these details are not quite clear yet. It's almost impossible to navigate these issues without getting at least some basic legal advice and investing a fair bit of time. Unfortunately, as often is the case with EU re…

> As a company that uses third-party services for data processing (which includes almost every piece of SaaS-type software) you have to sign a data processing agreement with each of those, which can mean considerable effort. At least for SaaS it's pretty clear-cut. For freelancers, contractors and consultants the situation is way more confused. AFAICT I need a data processing agreement with every client, even if I on…

IMHO it simply requires companies to make a clear choice.

Either they have the organizational capacity to handle private information properly, or they should not do it at all.

There's no reason for every company to get a data processing agreement with every SaaS they use as long as they're not putting private data of other people inside; and in most cases (except CRM and payment systems) they should not do so. There's no reason for every random company to get a data processing agreement with the contractor maintaining their WordPress site if that site doesn't contain any private information, and it probably should not. On the other hand, if it does, then giving full access to that data should be more difficult than simply giving the keys to a random contractor; the company is fully responsible for whatever you do ("Where processing is to be carried out on behalf of a controller, the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of this Regulation and ensure the protection of the rights of the data subject."), so that includes vetting you, being able to supervise what you've done, and probably some liability requirement. On the other hand, if that's a standard service you're providing, it all means that your standard agreement form just needs a few extra paragraphs to cover that data processing part.

The log/IP address issue has technical solutions - you can use logrotate in combination with gnupg to ensure that logs are available if you need to analyze them, but are encrypted and not available to everyone logging on that server.

Re: How GDPR Will Change The Way You Develop

#446

Earlier quoted context omitted.

I'm not sure what you mean by "holes". It seems like it's a fundamental and intended feature of the GDPR that you can't achieve compliance-by-default. You have to explicitly audit every interaction between every system you have, to ensure that either no personal information is present or the interaction complies with GDPR standards.

" ...you have to explicitly audit every interaction between every system... " But would you though? If you're a large co. you'd have a configuration management system where you just pull the specs/data rather than do an audit. If you're a small co. you'd know already, and if not you'd just go look. Right? My experience is that anyone complaining about the amount of work GDPR is causing is a. not compliant anyway (and…

"has terrible or no IT governance"

So planet earth then. Consequences must be understood in terms of how things actually are even if the rules are ultimately for the best.

Re: How GDPR Will Change The Way You Develop

#447
post #188

Earlier quoted context omitted.

American engineer building a bridge or tunnel in EU is certainly going to know EU regulations. An EE designing circuits for EU needs to know about lead-free solder requirements. On the other side, Mies van der Rohe needed to work with a US-certified architect to build the Seagrams. Having been in the software industry for a while, it is often discouraging to see how both explicitly and often inadvertently move-fast-a…

Right, but the point is that you KNOW the country your bridge or tunnel is going to be used in, because you build it there. If I build a web app and deploy it on a server in California, it can immediately be used by people in almost any country in the world. Is it my responsibility to follow the censorship rules from China on my webapp in California? Is it my responsibility to know all the regulations on web apps fro…

If you don't do any business in the EU I'm not sure how the new law would apply.

Re: How GDPR Will Change The Way You Develop

#448

Earlier quoted context omitted.

> Imagine the EU made a law requiring every country in the world follow their building codes whenever an EU citizen enters one of their buildings You are reaching. I give you a better example: it does not matter where a building part is being produced, if it ends up in a building in Europe it needs to be up to the local building codes and to the regulations of the single market.

You think I am reaching, but the GDPR does act this way. Lets say your visiting the USA as an EU citizen and you get a pizza delivery from a local small pizza shop. They put your name and delivery address in their computer in an MS Access database that makes stickers, emails the delivery guy's gmail account and a person delivers a pizza to you. They have no idea your an EU citizen and they just put enough information…

You clearly don't know what you are talking about.

Article 3 clearly states that it applies to

> the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or

> the monitoring of their behaviour as far as their behaviour takes place within the Union.

It does not apply EU citizens while traveling outside of the EU. It applies when you are monitoring or offering goods or services to someone in the EU.

Re: How GDPR Will Change The Way You Develop

#449

Earlier quoted context omitted.

> Lets say your visiting the USA as an EU citizen and you get a pizza delivery from a local small pizza shop If that pizza store has no relation to the EU then there is no legal ground by which the GDPR could become relevant. There is no treaty which would establish some sory of leverage here. //EDIT: which btw is unlike FATCA for which there actually are bilateral agreements.

You don't need a treaty to enforce the law, you just need a pizza shop owner who likes to vacation in europe sometimes. You carry out the default judgement if they ever arrive in the EU. The GDPR explicitly has a very global scope because it is targeting companies in and out of the EU. I wouldn't really have much of a problem with the GDPR if it had some small business and non-eu business exceptions. It doesn't and r…

How is that different from say Dimitry Sklyarov, a Russian who broke a US law while living in Russia, who later goes to the US for a convention and gets arrested and thrown in jail?

Re: How GDPR Will Change The Way You Develop

#450

Earlier quoted context omitted.

Yes, but like with all this stuff: Your intent to comply with the law carries a lot more weight than actual compliance in edge cases.

That's not very comforting when your goal is avoid having unforeseen problems like being arrested on your European vacation due to violating a law that doesn't apply to your country but you still violated because it applies to all EU citizens regardless of their geographical location.

> it applies to all EU citizens regardless of their geographical location

It does not. Article 3[1] clearly limits it to people in the EU. It says nothing about applying to EU citizens.

[1] https://gdpr-info.eu/art-3-gdpr/

Post reply on HN