Earlier quoted context omitted.
You know for things like being able to do analysis. For example, last week I wanted to know where to locate our next local server and so needed to know where the usage growth was coming from. I happen to noticed that the usage over the last few weeks was quite different to the historical data. If I only had 2 weeks of data I would have made our service worse for our customers.
You can't use one of the lawful basis of consent for this? https://ico.org.uk/for-organisations/guide-to-the-general-da...
How GDPR Will Change The Way You Develop
471–480 of 710 posts
Re: How GDPR Will Change The Way You Develop
#472The US withdrawing from the TPP was a (very) good thing: https://www.taylorwessing.com/globaldatahub/article-the-tpp-... The EU's war on memory is concerning. It will be used as cover for their social engineers. Misinformation campaign didn't work out? Ah, delete it!
Re: How GDPR Will Change The Way You Develop
#473Earlier quoted context omitted.
Yes the first 90% is reasonable, it is the last 10% that is a nightmare. I comply with the general intent (always have), but the law as currently written is near impossible to comply with. My feeling is this will be realised by the EU and a more rational set of guidelines will emerge.
Acting in good faith is the best protection you can have. In your case if there are parts that you can not comply with I would note these as clearly as possible and disclose those specifically to customers and why you can't comply with them. And another thing you could do is to get yourself a $500/hour lawyer specializing in privacy for an hour or two to tell you what to do on a sheet of letterhead.
Since we are not based in the EU and don’t have a business presence there I think I might just keep following the intent and wait for the EU to be more sensible.
I really do wonder how EU companies are going to comply with all this. What an enormous waste of resources to catch a few bad actors.
Re: How GDPR Will Change The Way You Develop
#474Earlier quoted context omitted.
The EU is going to send over its army and force you to comply. My understanding is the GDPR applies to residents of the EU, not just citizens, and it also applies when they are outside the EU. In practice this means it is impossible to determine if it applies unless you gather far more information than you really need from your users - “sorry we have to invade your privacy to protect your privacy”.
So a US company providing services to a US naturalized citizen in the US that is also a dual citizen of a country in the EU makes the company liable to follow these regulations? That makes no sense. This sounds unenforceable.
Yes the regulations make no sense and they really aren’t enforceable outside of the EU.
Re: How GDPR Will Change The Way You Develop
#475The US withdrawing from the TPP was a (very) good thing: https://www.taylorwessing.com/globaldatahub/article-the-tpp-... The EU's war on memory is concerning. It will be used as cover for their social engineers. Misinformation campaign didn't work out? Ah, delete it!
Please. Enough with the groundless conspiracies. There are no misinformation campaigns coming out of the EU or any other liberal democracy.
Re: How GDPR Will Change The Way You Develop
#476I really don't think (and I am developer, I will need to comply) that anything in GDPR is hard to understand. Treat data from others in same way as you would treat (and you are treating) yours. You are not selling your personal details to 3rd parties, you are not keeping painfull pictures of yourself climbing to garbage bin and doing diving completely drunk, you are not storing them into pastebin or unsecured databas…
If only it was that easy. A reasonable reading of GDPR makes standard web server logs (which contain IP addresses) a punishable offense, even if you don’t have a nexus in Europe. GDPR is a wonderful idea that will be insanely expensive to comply with, act as a continuous drag on developing new technologies, and end up offering only nominal protection to end users. This is just going to be another way for EU regulator…
Re: How GDPR Will Change The Way You Develop
#477Earlier quoted context omitted.
Acting in good faith is the best protection you can have. In your case if there are parts that you can not comply with I would note these as clearly as possible and disclose those specifically to customers and why you can't comply with them. And another thing you could do is to get yourself a $500/hour lawyer specializing in privacy for an hour or two to tell you what to do on a sheet of letterhead.
Great another shake down by a lawyer :( Since we are not based in the EU and don’t have a business presence there I think I might just keep following the intent and wait for the EU to be more sensible. I really do wonder how EU companies are going to comply with all this. What an enormous waste of resources to catch a few bad actors.
Of course, for the policymakers, it's a win, because as part of a rent-seeking bureaucracy, they can expand their empires as they produce more policies.
Re: How GDPR Will Change The Way You Develop
#478Earlier quoted context omitted.
Yep. It is worse that it can be a EU resident (non-citizen) visiting the the USA using a USA only service and the law as currently written still applies. Good luck. The next fun job is working out how to remove the data from all your backups when you get a removal request. I have taken the approach that I will comply with the general intent of the GDPR (which I did long before it existed), but not try to apply the ri…
"Yep. It is worse that it can be a EU resident (non-citizen) visiting the the USA using a USA only service and the law as currently written still applies. Good luck." You're going to have to provide proof to back up that statement.
"The principles of, and rules on the protection of natural persons with regard to the processing of their personal data should, whatever their nationality or residence, respect their fundamental rights and freedoms, in particular their right to the protection of personal data.”
0. http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX...
Re: How GDPR Will Change The Way You Develop
#479I really don't think (and I am developer, I will need to comply) that anything in GDPR is hard to understand. Treat data from others in same way as you would treat (and you are treating) yours. You are not selling your personal details to 3rd parties, you are not keeping painfull pictures of yourself climbing to garbage bin and doing diving completely drunk, you are not storing them into pastebin or unsecured databas…
If only it was that easy. A reasonable reading of GDPR makes standard web server logs (which contain IP addresses) a punishable offense, even if you don’t have a nexus in Europe. GDPR is a wonderful idea that will be insanely expensive to comply with, act as a continuous drag on developing new technologies, and end up offering only nominal protection to end users. This is just going to be another way for EU regulator…
Actually, it's more like a giant gift to Google and Facebook: GDPR borders on regulatory capture, with only the giants really having the resources to comply properly. This will hurt startups and smaller firms far more than it will the big dogs with their armies of compliance lawyers.
Re: How GDPR Will Change The Way You Develop
#480Earlier quoted context omitted.
You're referring to express consent. However, the user is granting implied consent - they're the ones visiting our website, they're the ones requesting our images and executing our javascript, and they're the ones filling out our forms. We're not forcing them to do any of these things.
Extreme example: you are standing in the way of my car.