Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

491–500 of 833 posts

Re: GDPR: Don't Panic

#491
post #358

Earlier quoted context omitted.

There is nothing - and I do mean nothing - written into the GDPR that requires any warnings of any kind, or places any limits on fines, except for $10/$20 million or 4% of revenue, whichever is greater. Period. A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR. The idea that "yes it says that but we can trust EU regulators to not assess large fines against foreign…

> A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR Come on, this is just scaremongering. Newsflash: If you run a business, you are already responsible for adhering to hundreds of other laws in which the fines could reach millions. But you don't see people running around screaming that the world is ending, because they know that the laws will generally be applied f…

> you are already responsible for adhering to hundreds of other laws in which the fines could reach millions.

Source please?

> If you are going to crank the anxiety to 10 every time a situation like this occurs, you probably shouldn't be running a business or handling others' data in the first place.

I'm not running one right now. It's not the situation that give me anxiety, it's just that it no longer seems interesting to support European customer for a potential business if that imply that I risk that much over their information. They just removed a big bunch of potential customer for a potential company. I would already try my best to limit the amount of PII but there's many time you just can't.

I'm from Quebec. Here we have laws over lottery. You know what it imply? If you make a lottery here in Quebec, you need to follow some simple regulations (I personally know people that did it essentially for fun (not for profit)) so they are pretty easy to follow, and pay the taxes for the winner. You know what I had to endure each time I went on an online contest, a broad exclusion because it was just not worth it to follow theses regulations. It's crazy the number of contest where you could literally do CTRL+F "Quebec" in the rule and find our little province (nowadays I see more of "where law forbid it" or stuff like that, but I haven't try to participate for a long time on a contest either).

Do theses companies had too much anxiety for our regulation? None at all, they were some multi billions companies that did this. It was just not worth it.

Re: GDPR: Don't Panic

#492
> The GDPR is going to expose me to fines of up to 20 million Euros for even the slightest transgression > No, the GDPR has the potential to escalate to those levels but in spirit

So, yes, but maybe no?

Re: GDPR: Don't Panic

#493
post #472

Earlier quoted context omitted.

For 20+ years the US - as the dominate controlling agent regarding the Internet - ensured the modern (post early 1990s) Internet remained extremely non-regulated and non-interfered with by ~195 nations (when it came to the global Internet system). It worked globally out of the gate and required no special adherence to US laws. The Chinese did not have to adopt US freedom of speech approaches to use the Internet. The…

While I agree the US was generally benevolent, it did it because it knew it had the tech superiority. It's the same thing with the Opium Wars and China or Perry's gunboat and Japan: we'll force you to trade with us because we know our goods are superior and you'll buy them. Same thing with the internet: the US was the biggest developed country, it had a large, stable, rich internal market, it had big universities chu…

> Will the US be as benevolent and open when it's the underdog?

US benevolence will increase in direct proportion to the extent that it isn't the sole global superpower (realistically it has been the sole superpower since WW2, the USSR power projection was mostly a facade, as it always had a terrible economy). Its perceived role as global policeman, has put it into an endless number of ridiculous positions (both politically and militarily). The less the US believes it has to be the prime actor in that regard, and the more the US has to inter-operate with everyone else in a normal fashion, the less obnoxious it will be about a lot of things. It will be able to semi-normalize back to closer to how other major nations behave.

Obviously the US will remain an outsidzed global superpower. Its economy and military scale alone will ensure that. However the coming future in which China is a real rival that can stand toe to toe, will force a number of fascinating adjustments to all politics around the globe (and I mean not just to US politics, all politics for all countries).

The real question to ask is, will China be benevelont with its future power? Look at what they're doing to their people right now for the answer (vast Muslim torture camps like the Mao days, where people are being forced with violence and psychological torture to give up their Islamic beliefs; literally torturing homosexual people to convert them away from homosexuality; restricting "homosexual speech" because it's anti-Socialism; wiping out what limited speech the people of China had acquired; using its military to annex the South China Sea away from its neighbors, which is 4x the size of France or Texas; etc). Now consider for a moment that that is China just getting warmed up as a global power, and consider what other horrific things they may choose to do under dictator Xi (dictatorships have a near universal record of getting worse, rather than better, as it pertains to human rights).

Consider that China has begun an aggressive expansion of its military outside of its borders (laying down plans to build numerous foreign military bases to give it global projection capability). Now one might fairly criticize the US for its global military expanse; however the US hasn't used its might to annex nations or territory globally, it hasn't actually acted as a traditional empire (ie Ramstein military base in Germany is no threat such that the US might suddenly attempt to annex Germany). Meanwhile China routinely threatens to invade Taiwan and annex it, they get upset if you so much as recognize Taiwan as an independent nation or talk to its leader directly. Maybe next week China will decide that Mongolia too is a proper part of the greater China strategy.

So with that growing power, is China suddenly going to become a soft benevolent giant? Or will they get worse? I think the answer is obvious and the planet should be terrified about what's coming. The entire Chinese approach is incompatible with democratic values across the board, and they are without question going to throw their weight around as it pertains to censorship (they already are). They're currently busy buying up Eastern Europe and using their investments to get countries like Greece to block actions against them as it pertains to eg the South China Sea. Imagine a world under the reign of Xi, forced by threat (direct or implied) to comply with how the the CPC operates China today. If people thought the US superpower behavior was bad (a democratic nation with vast human rights protections), that's going to be 10x worse.

Re: GDPR: Don't Panic

#494

I don't think it's really that simple. especially the deletion requirements. There are just so many IT systems that really don't support deletion. An absolute worst case I can imagine is GitHub being asked to delete an account which had commits in multiple large projects. Are they going to alter those projects source code?

This is already a “solved problem” though. If you post copyrighted material to Github, Github will have to remove it. If you’re posting users information to a public repo, then you fully deserve whatever impacts you’ll face when you have to delete it.

I'm not talking about copyrighted or otherwise shady stuff pushed to GitHub. My concern is what's supposed to happen when a GitHub user requests GitHub to delete their entire account and all the personally identifying information they have on them. Clearly GDPR calls for this to be possible, yet that would mean that GitHub would have to delete this user's commits (which usually contain full names and mail addresses). Clearly they can't reasonably do that though.

Re: GDPR: Don't Panic

#495

Earlier quoted context omitted.

Good lord, it's like you didn't read the article. Or, you're fine with a competitor who isn't afraid of entirely reasonable international laws coming in and eating your lunch.

We ran the numbers on how much it would cost to establish compliance, and with that alone it was barley worth it based on the current EU customer base we have. We also considered all the additional liability we’d be taking on, and with that alone it was barely worth it based on the current EU customer base we have. We’d also be very happy if one of our competitors started investing in the EU market. It’s worth about…

>(and investing in compliance with European - absolutely not international - regulations)

Did you think about this before typing?

Clue: how many countries does an EU-wide law directly apply to? One? Or many?

Re: GDPR: Don't Panic

#496
> The EU regulators see their job as ensuring compliance, not as creating a source of income.

I thought one of the objective of EU is to make US social media pay their fair share. Citing same article:

> European holdings or that use the EU to avoid paying taxes rightly worry about this particular aspect

So, what is it?

Re: GDPR: Don't Panic

#497

Earlier quoted context omitted.

> It turns out that the vast majority of contractors and freelancers were operating in that fashion legitimately and continue to do so Which we know is definitely NOT the case for companies storing your data correctly.

Are you claiming that most companies are not storing data in compliance with current law today? There's a meme about how all businesses are trying to exploit personal data mercilessly at any cost, yet among the small businesses around here and the people I know who work there, none of us is in that line of work, nor I suspect would any of us want to be.

I do not believe that the vast majority of companies which are significantly impacted by the GPDR were storing data in a reasonable manner, no.

Having to spend some effort to make sure you are in compliance with a huge new piece of regulation is expected and I understand that people complain about having to do it. However, after the initial bring-up pains any business which continues to have a problem with the GPDR most likely has a business model directly in conflict with the spirit of the law.

Re: GDPR: Don't Panic

#498

Earlier quoted context omitted.

"his belief that everyone working in GDPR enforcement in the EU will not only be totally predictable and reasonable today but also going forward into the indefinite future." EXACTLY! There seems to be an almost cultish devotion to the benevolent institution that it can do no wrong, neither now nor henceforth. I understand WHY people have this belief. The EU is under constant attack at the moment from many sides, and…

> EXACTLY! There seems to be an almost cultish devotion to the benevolent institution that it can do no wrong, neither now nor henceforth. You have to trust someone. Either the vast expanse of companies clearly mishandling your data, or the "benevolent" body which so far at least has a fairly good track record. It's not perfect. It's dangerous to give them too much power because you don't know how they will change in…

A fairly good track record in which its own member states are constantly threatening to leave and one has already successfully left. As an American lokoing in from across an ocean, it does not look like a stable region that I would put trust in

Re: GDPR: Don't Panic

#499
post #445

Earlier quoted context omitted.

Then they can just do that. I'm sure other companies will be happy to scoop up that business.

We’d be quite happy if that happened. Seeing our competitors investing in Europe would simply mean less competition in markets with much greater growth.

Sounds like that's a solution everyone can be happy with!

Re: GDPR: Don't Panic

#500

Earlier quoted context omitted.

Where did I advertise misuse of our customers data? Compliance and privacy are not the same thing, just like compliance and security are not the same thing. We have a great privacy policy and we don’t misuse our customers data in any way. For us, it didn’t make sense to invest the amount of money we’d have to to establish compliance with the GDPR, or to invest in maintaining that compliance, and the liability that GD…

You are advertising that your handling of personal data is so haphazard that GDPR compliance would be expensive. You are admitting that you aren't good enough for the EU, and therefore that you aren't very good in general at whatever you do. I expect that, at least in some obviously global markets like most e-commerce, GDPR compliance (as opposed to throwing the towel like you) will be treated like a certification of…

I’m sorry, but this is simply the naive opinion of somebody that has clearly never had to deal with compliance before on a meaningful level.

My customers are all happy with my privacy policy, and not a single one outside of the EU has expressed any interest at all in the GDPR. We are actually compliant with a majority of the regulation, however there are some areas where we would have to re-architect to gain full compliance.

This is not in anyway a signal that we’re “not good enough” to handle our customers data. It is mostly a sign of a poorly written piece of regulation, that has more undefined edge cases than it has defined use cases.

We’re not going to be the only company that comes to this conclusion, so you can go around slandering anybody you like, but that’s not going to change the facts behind what is a rather simple business decision for a lot of people.

You’re incredibly naive if you think complying with regulations like this is going to be cheap and easy, and your even more naive if you think that compliance is going to mean anything other than a rubber stamp. I’ve seen PCI, Fedramp, ISO27k, SOC2... organisation that have been certified as compliant, but were in reality less than 10% compliant. The compliance industry is a joke worldwide, and everybody knows it.

Post reply on HN