Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

51–60 of 833 posts

Re: GDPR: Don't Panic

#51

Here in UK I have been receiving about 5-10 emails a day from various companies - most of whom I don't remember - telling me I need to sign up again so they can keep my details and keep spamming me. Fantastic.

Same here, finally recruitment agencies will unsubscribe me from jobs offers that I'm totally not interested in. I used to get a few emails per week asking me if I'm interested for relocation and work in [insert programming language I have no experience in]. I asked them many times to stop emailing me this crap, they never did until this week :)

Re: GDPR: Don't Panic

#52

Earlier quoted context omitted.

Am in EU, am involved in some compliance stuff and have talked to plenty others at other companies, and it really does seem to be a nothing-to-see-here for all companies except the sleezy ones.

In all of my research, talking to lawyers, and seminars on GDPR, it is about: 1. Ask permission for collecting data 2. Keep sensitive data safe 3. Restrict access to said data 4. Keep a log of what happens with the data 5. Delete it upon request 6. Have all of the above documented and adhere to the protocol. It's such a none issue unless you're relying on the very thing GDPR is designed to combat. If you not collecti…

Completely agree with everything you list, and would add that 6. you can't force a user to give up privacy in order to get some other benefit, e.g. you can't offer to unlock some feature in return for more tracking

Re: GDPR: Don't Panic

#53

> I was actually surprised by how easy it is to read it there's a whole two hundred post debate around here whether ip are or aren't pii on their own, with the wast majority holding the wrong position. there's a whole branch of gdpr that people aren't considering, which is not related to software but to your business (i.e. your mail calendar). you also need a privacy policy if you are receiving phone calls. did you k…

>there's a whole two hundred post debate around here whether ip are or aren't pii on their own.

Largely pointless. EU courts have in the past ruled that IPs are personal data because they can be tracked back to a person. End of story.

>there's a whole branch of gdpr that people aren't considering, which is not related to software but to your business (i.e. your mail calendar).

was largely already covered by the previous EU privacy law and the german privacy law. Courts largely agree that calendars for appointments are fine as long as you keep them reasonably secure and don't throw them around in public.

>you also need a privacy policy if you are receiving phone calls. did you know that?

Yes I did. I informed myself when I registered as a small business.

Re: GDPR: Don't Panic

#54
post #48

This doesn't consider some factors that dictate how strong any company will experience their firehose of GDPR requests to be: - how incentivised people are to make GDPR subject access requests of the company (how angry, confused, hostile curious they are) - how easy it is for them to make requests (entirely manual vs. online service) - wildcard factors (internet flash mobs bent on vengeance against a corporate) There…

I agree, and there seems to be a lack of conversation around this! Next week could be ground-zero for all sorts of unintended consequences. Especially, a flashmob of GDPR requests could sink a company.

Re: GDPR: Don't Panic

#55
post #48

This doesn't consider some factors that dictate how strong any company will experience their firehose of GDPR requests to be: - how incentivised people are to make GDPR subject access requests of the company (how angry, confused, hostile curious they are) - how easy it is for them to make requests (entirely manual vs. online service) - wildcard factors (internet flash mobs bent on vengeance against a corporate) There…

This sounds like the arguments that organisations make against freedom of information laws. There is that risk, but what is the alternative? There doesn't seem to be a middle ground to me - either people can make subject access requests or they can't.

Re: GDPR: Don't Panic

#56
post #48

This doesn't consider some factors that dictate how strong any company will experience their firehose of GDPR requests to be: - how incentivised people are to make GDPR subject access requests of the company (how angry, confused, hostile curious they are) - how easy it is for them to make requests (entirely manual vs. online service) - wildcard factors (internet flash mobs bent on vengeance against a corporate) There…

> The candidate gets back a formatted dump by email of all sorts of recruitment data, including interview notes, etc.

Unless data is removed before end of the process and company keeps only final outcome. ;)

Re: GDPR: Don't Panic

#57

I'm not sure about the point regarding the DPD. EU Directives themselves don't have teeth, but they're supposed to be transposed into national laws - e.g. the DPA in the UK - and would be enforced nationally. A regulation comes into law across the EU, but is still often transposed, and the enforcement mechanism (to begin with) is still basically the same. He's right that the DPD was not well-adhered to, though.

The problem with the laws stemming from the DPD was that there were different laws in each EU country, and the enforcement options were too weak for slippery international corporations.

One critical change in the GDPR is the mandatory reporting of significant breaches. Before, it was entirely optional, so reports could come out years after the even once the material surfaced online.

Re: GDPR: Don't Panic

#58

There's currently no case law surrounding GDPR. Moreover, some elements of the GDPR are up for interpretation. People are rightfully concerned. > "This post is an attempt to calm the nerves of those that feel that the(ir) world is about to come to an end" This post is actually a single person's viewpoint, a mere speculation of how things may or may not turn out to be. Your mileage may vary.

I guess we should only enact new laws which already have established case law. /s

Re: GDPR: Don't Panic

#59
I can't help but love the turmoil GDPR is causing in the adtech "industry". Like wasps buzzing around the exterminator who's about to destroy their nest.

Re: GDPR: Don't Panic

#60

I was hoping for a nice respite to the anti-GDPR stuff we've seen recently, but this is just naked propaganda. In particular, the sentence: "the GDPR has the potential to escalate to those levels but in the spirit of the good natured enforcers ..." The author seems to have the idea that bureaucratic EU systems are inherently "good" and that even if things look bad on paper, it will be fine because they are "good" peo…

I think this is a very distinct difference between the EU with the scaremongering removed, and e.g. the US: My experience of the EU has been that they've consistently looked out for my interests. Even in the face of the local government (I live in the UK) that have kept fighting for positions I find abhorrent (e.g. UK governments keep complaining about having to abide by EU human rights regulations for example).

Yes, we shouldn't aim to give governments power to push things to an extreme, but on the other hand we should also ensure that they have the ability to actually react to serious abuses.

In particularly in the area of data protection, I don't know of a single example where the rules have been pushed to the extreme. If anything, as a private citizen I'm disappointed there's not been stricter enforcement. As someone who has had to deal with it on the corporate side as well, it's not been hard to comply with.

Enforcement here is generally always strongly predicated on not jumping straight to the strictest possible outcome, but in carefully considering how serious a transgression is. It's not that EU systems are inherently good, but that history and practice have shown that when they give flexibility, it takes serious abuses and ill intent to end up with the strictest reactions allowed, and there'd also be little reason to assume that anyone rushing to the strictest interpretations possible wouldn't get shut down hard by the courts.

Post reply on HN