Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

441–450 of 833 posts

Re: GDPR: Don't Panic

#441

Earlier quoted context omitted.

There is nothing - and I do mean nothing - written into the GDPR that requires any warnings of any kind, or places any limits on fines, except for $10/$20 million or 4% of revenue, whichever is greater. Period. A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR. The idea that "yes it says that but we can trust EU regulators to not assess large fines against foreign…

I think you and everyone making similar points in this thread are getting tripped up by the difference between rules-based regulation and principles-based regulation. This is unsurprising, given that the US is so heavily rules-based, but the EU (certainly the UK) has a long history of principles-based regulation. In rules-based regulation, all the rules are spelled out in advance, and the regulator is basically an au…

An advocate of rules-based regulation would say this can make regulators unpredictable and capricious.

Unfortunately, so might students of history. Ask anyone in the UK who was working in the freelance or contract world when IR35 was introduced.

In that case, too, the principle was reasonable enough: there was a loophole in tax law where you could decide you're a contractor instead of an employee and pay less money despite for all other practical purposes still being an employee, and this was being actively exploited by some people.

In that case, too, the reality was that most people working in the sector probably wouldn't be challenged by the authorities, not least because the enforcers had limited resources.

But in that case, too, a given individual's status was often unclear. While some of those who were deterred or subsequently received penalties really were engaging in obvious tax avoidance, other reports described crippling penalties for people whose arrangements appeared to have been quite reasonable but to have fallen foul of someone in government's dubious interpretation.

This led to substantial amounts of time and money being collectively spent by the freelance and contractor community incorporating new legalese into contracts and paying for advice and taking out insurance policies. An entire trade body was formed primarily to deal with this threat. Even today, those of us who take on any sort of individual contract or freelance work from time to time have to be careful not to say or do certain otherwise reasonable things, or to allow others to do so, for fear of tipping the balance or giving any appearance that might be subject to challenge.

And the irony is that while the law arguably had some effect initially in getting contractors to go back to being permies if they were just using it as a tax dodge, overall it appears that IR35 has raised very little extra tax revenue for the government. It turns out that the vast majority of contractors and freelancers were operating in that fashion legitimately and continue to do so, and most enforcement actions appear to fail to the extent that the government even tries any more. Nevertheless, the rules still hang like a sword of Damocles above the whole sector.

Re: GDPR: Don't Panic

#442

Earlier quoted context omitted.

No. That is just plainly wrong. GDPR allows for tracking without opt in. It just needs to enable you to opt out of being tracked with for example a link to opt out in the privacy policy page. Something I still plan to make more visible (in the footer or something like that), but is already there [0]. These so called cookie layers are not necessary for tracking. They are not even necessary for first party on site adve…

First of all i did not mean to make you change your blog site - I was just pointing out that the law applies to everything no matter how small. Second, are you sure about this? My understanding is that if you use third-party tags such as analytics you need to get consent from users and not to use them if they don't consent. One other thing that is not clear to me is if we need cookie prompts, and how can we implement…

IIRC, the cookie law applies only to third party cookies. So you can freely set a first party cookie to store their opt-in/out.

Re: GDPR: Don't Panic

#443
post #80

Earlier quoted context omitted.

But that's purely your own opinion. I do have some direct experience of working with EU data protection regulators. My experience has been that they vary wildly in "reasonableness". UK ICO is pretty OK, they want companies to succeed. France's CNIL is a joke. Petty, spiteful and utterly inconsistent. I watched as a company worked closely with them to get their sign-off on a change to their terms of service and privac…

"his belief that everyone working in GDPR enforcement in the EU will not only be totally predictable and reasonable today but also going forward into the indefinite future." EXACTLY! There seems to be an almost cultish devotion to the benevolent institution that it can do no wrong, neither now nor henceforth. I understand WHY people have this belief. The EU is under constant attack at the moment from many sides, and…

> EXACTLY! There seems to be an almost cultish devotion to the benevolent institution that it can do no wrong, neither now nor henceforth.

You have to trust someone. Either the vast expanse of companies clearly mishandling your data, or the "benevolent" body which so far at least has a fairly good track record. It's not perfect. It's dangerous to give them too much power because you don't know how they will change in the future. But at the end of the day, I'd rather trust a governmental body which is at least supposed to look out for my interests, rather than a company whose main motivation is to exploit me for every penny I have.

Re: GDPR: Don't Panic

#444

> As soon as you do business abroad you will have to comply with the laws of those countries. But are you doing business abroad, just because you're on the internet? Is it not the customer who is coming to you to to do their business abroad, while you do your business in the country you live in?

The author claims that local law compliance has always been the case. That is in fact incorrect and is a glaring mistake in the article. For the first 20 years of the Web's popular usage globally, you in fact mostly did not have to comply with local laws when it came to commerce online - there were few laws, and most jurisdictions had yet to flesh out how they were going to regulate and apply their laws or not. You simply opened up shop and sold to anyone from anywhere that wanted to buy from you, and you did not need to give a second thought to anything else.

Coming next is a global compliance nightmare. If you want to sell globally, you'll have to comply with dozens of unique local approaches. Small businesses won't stand a chance of being able to deal with that. An army of fee charging middle-men will spring up offering solutions, extracting fees accordingly.

Re: GDPR: Don't Panic

#445

Earlier quoted context omitted.

I think you and everyone making similar points in this thread are getting tripped up by the difference between rules-based regulation and principles-based regulation. This is unsurprising, given that the US is so heavily rules-based, but the EU (certainly the UK) has a long history of principles-based regulation. In rules-based regulation, all the rules are spelled out in advance, and the regulator is basically an au…

>and you'll have to engage with it on those terms Or you can just disengage with Europe all together, which is an obvious choice for many small to medium sized companies, given the risks and costs involved.

Then they can just do that. I'm sure other companies will be happy to scoop up that business.

Re: GDPR: Don't Panic

#446

Here in UK I have been receiving about 5-10 emails a day from various companies - most of whom I don't remember - telling me I need to sign up again so they can keep my details and keep spamming me. Fantastic.

I bought something on Ebay and the Ebay seller has been spamming me with offers ever since. I didn't sign up to any newsletter. I was not aware that such thing would even be possible with Ebay.

Now they sent me a message telling me that I should sign up again on their website to continue getting their messages. No thanks.

Re: GDPR: Don't Panic

#447

I think much of this probably comes down to cultural and ideological differences between the US and the EU. It certainly seems that almost all of the rabidly pro-GDPR crowd is from the EU. Interesting: I have a number of anti-GDPR comments here and on last night’s GDPR thread that got upvotes last night US-time, heavily downvoted throughout the night, and are now going back up :)

> It certainly seems that almost all of the rabidly pro-GDPR crowd is from the EU.

Hey, from my viewpoint the rabidly anti-GDPR crowd is from the US :p

Re: GDPR: Don't Panic

#448

I think much of this probably comes down to cultural and ideological differences between the US and the EU. It certainly seems that almost all of the rabidly pro-GDPR crowd is from the EU. Interesting: I have a number of anti-GDPR comments here and on last night’s GDPR thread that got upvotes last night US-time, heavily downvoted throughout the night, and are now going back up :)

Yeah what a surprise?

Imagine a global paparazzi law banning photos of celebrities from being published without explicit consent.

Celebrities would be happy. Paparazzis and magazine readers not so much.

Re: GDPR: Don't Panic

#449

Earlier quoted context omitted.

It's not like if the US laws didn't have any extraterritoriality. This is a disingenuous argument. The US has never passed a law that is this easy to violate outside of its own borders, is this ripe for abuse, and carries such enormous penalties and burdens for essentially everyone in the world that wants to operate a website. In fact, no country has ever done this before. GDPR is different, and not in a good way.

Lol, the US has FATCA which makes it very difficult for fin-tech startups to work with americans. I'm an e-resident of Estonia, and almost all financial services state they cannot serve US clients.

*FATCA ;)

Re: GDPR: Don't Panic

#450
post #313

Earlier quoted context omitted.

> I've probably spent a total of three to four days reading around the GDPR and I don't really see what's special about this law other than it's imposing decent standards on what was in effect a wildly unregulated industry in people's personal data We are still waiting for the first court battles that will help determine how GDPR is actually enforced in practice. Until then being in compliance with GDPR is gonna be l…

> We are still waiting for the first court battles that will help determine how GDPR is actually enforced in practice. I'm wondering if this is yet another point where cultural differences are muddling the discussion. In particular, the difference between common law systems (like the USA) and civil law systems (like nearly all of the EU).

this is a major difference indeed.

In Civil law systems, the judge his interpretation matters much less then in common law systems. Mainly because everything is already codified into law.

Post reply on HN