Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

471–480 of 833 posts

Re: GDPR: Don't Panic

#471

For those of you understandably intimidated by the GDPR regulations themselves, here's a good summary in plain English: https://blog.varonis.com/gdpr-requirements-list-in-plain-eng... The UK's ICO also has a good structured summary: https://ico.org.uk/for-organisations/guide-to-the-general-da... In general I agree with the sentiments in this article. I've probably spent a total of three to four days reading around th…

> people's personal data.

I remember back in the day there was no such concept on the internet. Your identity didn't translate to anything in real world. At somepoint people started to treat it as 'real world but on the computer' instead of thinking about it totally radically new way about 'self'/'identity' ect. People thought of their internet profiles as their own self. Intenet age was killed even before it started. Endless promise of internet to free human beings was thwarted by paranoia, censorship, laws ect.

Re: GDPR: Don't Panic

#472
post #427

Earlier quoted context omitted.

Are you American, by any chance? The whole internet dances to the US tune, legally. Welcome to our world :)

For 20+ years the US - as the dominate controlling agent regarding the Internet - ensured the modern (post early 1990s) Internet remained extremely non-regulated and non-interfered with by ~195 nations (when it came to the global Internet system). It worked globally out of the gate and required no special adherence to US laws. The Chinese did not have to adopt US freedom of speech approaches to use the Internet. The…

While I agree the US was generally benevolent, it did it because it knew it had the tech superiority. It's the same thing with the Opium Wars and China or Perry's gunboat and Japan: we'll force you to trade with us because we know our goods are superior and you'll buy them.

Same thing with the internet: the US was the biggest developed country, it had a large, stable, rich internal market, it had big universities churning out graduates (many of them coming from other countries!), it was the inventor of many tech things that make up the internet. So of course a less regulated internet would benefit it since its companies were best positioned to take advantage.

My guestion for the next 30-40 years: unless China screws up badly, it will overtake the US. It's simple math: a moderately rich Chinese population will overtake the US one, as it outnumbers it 4 to 1 or so. Will the US be as benevolent and open when it's the underdog?

Based on some reactions I've seen here, regarding the EU and the GDPR and also on reading a ton of comments about China, I'm not so convinced.

TL;DR: The US is reasonable, for a super power, but it didn't do it out of the goodness of its heart.

Re: GDPR: Don't Panic

#473
I can tell you that GDPR is going to cause issues with block based backups. Many hosting providers don't separate customers on different block devices. When you back up a block device you have snapshots that have many different organizations data on them.

Part of making good backups is knowing that the backup can't change. The only solution now is to add paths to go back and modify those backups to remove customer data when asked too.

That is my plight anyways.

Re: GDPR: Don't Panic

#474
post #336

Earlier quoted context omitted.

Privacy Shield starts at $500 per year for the smallest company, and that’s before you contract with a mediator (lowest cost there is $50/year if you use the EU options). Unless I’m missing the option for $250/year on their website?

I was referring to https://www.privacyshield.gov/Program-Overview where single framework (EU-U.S.) for companies with between $0-$5 million the yearly fee is $250. If you want to add Swiss-U.S. privacy shield as well, then $375 per year for both.

Thanks - I have no idea where I got the $500 number in my head. Maybe I was thinking of one of the private mediators I was researching? Sorry for questioning your initial number...

Re: GDPR: Don't Panic

#475

For those of you understandably intimidated by the GDPR regulations themselves, here's a good summary in plain English: https://blog.varonis.com/gdpr-requirements-list-in-plain-eng... The UK's ICO also has a good structured summary: https://ico.org.uk/for-organisations/guide-to-the-general-da... In general I agree with the sentiments in this article. I've probably spent a total of three to four days reading around th…

There is nothing - and I do mean nothing - written into the GDPR that requires any warnings of any kind, or places any limits on fines, except for $10/$20 million or 4% of revenue, whichever is greater. Period. A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR. The idea that "yes it says that but we can trust EU regulators to not assess large fines against foreign…

It doesn‘t need to be written there. It has been written elsewhere, long ago.

All state action is subject to judicial review, where proportionality is a big factor.

It‘s an aspect of due process that is being reviewed and enforced by every court, up to the constitutional courts.

Example: the German criminal code threatens „up to five years“ in prison for theft.

That does not mean that a first-time theft of a not-too-valuable object could get you five years. Impossible. But not written in the statute itself. But even if a court was mad enough to hand out such a sentence, the revision stage would be swift and without any uncertainty.

Actually, it‘s hard to conceive of a first-time theft-offender going to prison, instead of paying a fine or at least having the prison sentence suspended.

Re: GDPR: Don't Panic

#476

Earlier quoted context omitted.

The only thing I can do as a customer is be mildly amused at the fact that you're complaining it's inconvenient for you to respect my privacy now that a law is coming into effect forcing you to do so. From the other end of the spectrum, I know you're wildly exaggerating the difficulty of compliance.

It's not inconvenient, it's costing me money . I don't want your data, I need to collect it and store it to comply with other laws, now I need to verify that the particular way I collect and store that data isn't violating some other new law. You are not my customer , but even if you were, keep in mind that for every piece of regulation (and there's tons of it!) I need to fulfill, I have to pay, which means you need…

Did you actually look into the GDPR before jumping to these conclusions about the effects on your business? For example, if you have a legitimate need for user data (e.g. "I need to collect it and store it to comply with other laws") then the GDPR does not apply. This is very plainly laid out for those that care to actually inform themselves.

Re: GDPR: Don't Panic

#477
post #439

Earlier quoted context omitted.

I find it amazing so many companies are willing to advertise the fact that they will abuse their customers in the way you are doing right now.

Where did I advertise misuse of our customers data? Compliance and privacy are not the same thing, just like compliance and security are not the same thing. We have a great privacy policy and we don’t misuse our customers data in any way. For us, it didn’t make sense to invest the amount of money we’d have to to establish compliance with the GDPR, or to invest in maintaining that compliance, and the liability that GD…

> Compliance and privacy are not the same thing

I remember the time we had very good privacy policies but getting that project to be compliant with COPPA was still a significant effort, so I think I get where you're coming from.

Once we became compliant, quite frankly, I felt a lot safer and more confident in affirming that our privacy policies were very good. Maybe it was some kind of sunk cost syndrome, but I was glad we did (were forced to do) it.

Re: GDPR: Don't Panic

#478

Earlier quoted context omitted.

I think you and everyone making similar points in this thread are getting tripped up by the difference between rules-based regulation and principles-based regulation. This is unsurprising, given that the US is so heavily rules-based, but the EU (certainly the UK) has a long history of principles-based regulation. In rules-based regulation, all the rules are spelled out in advance, and the regulator is basically an au…

Wow I wish we had principle-based regulation in the US. It seems like rules are made specifically so that only wealthy, entrenched institutions can follow them without significant burden. When those institutions fail, the fines don't seem relative to profit or size of the company or anything.

I suspect it wouldn’t work in the US. Principles based regulation requires some level of concensus on principles. We don’t have that in the US. Polarization breeds rules worship because you don’t trust the other people to use their discretion.

Consider, for example, how every major social issue devolves into a Constitutional litigation. Whereas in Europe people just vote on stuff.

And as to regulatory approaches I think you’d be surprised. European regulation is often quite conservative.

Re: GDPR: Don't Panic

#479

Earlier quoted context omitted.

Wow I wish we had principle-based regulation in the US. It seems like rules are made specifically so that only wealthy, entrenched institutions can follow them without significant burden. When those institutions fail, the fines don't seem relative to profit or size of the company or anything.

I suspect it wouldn’t work in the US. Principles based regulation requires some level of concensus on principles. We don’t have that in the US. Polarization breeds rules worship because you don’t trust the other people to use their discretion. Consider, for example, how every major social issue devolves into a Constitutional litigation. Whereas in Europe people just vote on stuff. And as to regulatory approaches I th…

Oh totally agree. Just think about the DMV. The people who work there cite the law word with zero discretion. Most US companies are like that as well. It's quite dystopian.

Well lets say it wouldn't work with the current ruling class mindset where everyone they employ is stupid and unable to think critically.

Re: GDPR: Don't Panic

#480

Earlier quoted context omitted.

There is nothing - and I do mean nothing - written into the GDPR that requires any warnings of any kind, or places any limits on fines, except for $10/$20 million or 4% of revenue, whichever is greater. Period. A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR. The idea that "yes it says that but we can trust EU regulators to not assess large fines against foreign…

I think you and everyone making similar points in this thread are getting tripped up by the difference between rules-based regulation and principles-based regulation. This is unsurprising, given that the US is so heavily rules-based, but the EU (certainly the UK) has a long history of principles-based regulation. In rules-based regulation, all the rules are spelled out in advance, and the regulator is basically an au…

What you dub principles-based regulation others call trust-based regulation, or randomly-enforced regulation, or we-know-it-when-we-see-it-based regulation. Some don't appreciate this type of regulation.

I think the unfortunate thing is that, when the previous/existing incarnations of these protection laws were/remain unenforced, many assumed it was because of lack of "teeth". But those of us familiar with how these principles-based regulatory bodies work know that it's more about confusion and regulator apathy. Nobody here is watching the watchers. Instead, there's a bunch of people foaming at the mouth with pitchforks asking for more laws and dismissing alternative concerns as hysteria or not understanding how laws work. We should be discussing how to solve the problem, yet we continually devolve to discussing the government-led solution presumably because we feel helpless and can't consider better options.

Post reply on HN