Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

521–530 of 833 posts

Re: GDPR: Don't Panic

#521
post #502

Where is the form on this site that claims to be GDPR compliant to get my IP removed from the server logs?

Keep reading the rest of that paragraph:

> Well, this website is fully compliant with the law, so at least in this particular case it seems to work. Why? Because I don’t store any information about you. That’s a conscious choice on my part which I made long before the GDPR was even talked about in public. But if your situation is more complex then you too can be compliant, or at least - and this is key - you could try to be compliant. For instance, one oft heard argument is that no webserver (or even any internet service) is going be able to be compliant because all web servers log IP addresses, and IP addresses are PII. But that argument does not hold water. There are several reasons for that, the major ones being: webservers only log IP addresses if you configure them to do so. Almost all webservers have a formatting option that determines what exactly is logged and you could configure your webserver to not log the whole address but just the network portion. You also have the option to log the address and to disclose that you do so in your privacy policy, but then you will have to allow for the removal of that data on request, which you may find burdensome (or not, that depends on the volume of such requests). Finally, you may have a legitimate reason to log the IP address, provided you delete it after you are done with whatever use you collected it for in the first place. There is enough room in the GDPR to hold on to the address for 30 days with a possible extension of another 60 days after which an automated reply to the user can tell them their IP address was purged and you’d be in compliance. That’s one of the reasons why I think the GDPR is a surprisingly good law, most of the times when legislation is written that impacts technology the end result is absolutely unworkable, in this case most scenarios seem to work well for all parties involved.

Re: GDPR: Don't Panic

#522
GDPR puts into jeopardy the business model that almost every consumer internet business has run on, post internet bubble: advertising.

That's what is at jeopardy here and nobody is willing to just say it.

Don't agree with the concept of tracking users to serve them ads? Great, make the case that GDPR ends the scourge of advertising subsidized applications as services.

Let's not ignore it though. The reality is, a lot of internet companies that consumers use and like, rely on either selling advertisers access to their market or sell user contact data outright, because there is no other way to make money.

If the argument is that this is an unethical and harmful way to keep services alive then we need to agree that the bulk of the last 20 years of startups business models are broken and what the implications for future internet business models are.

Re: GDPR: Don't Panic

#523

Earlier quoted context omitted.

We ran the numbers on how much it would cost to establish compliance, and with that alone it was barley worth it based on the current EU customer base we have. We also considered all the additional liability we’d be taking on, and with that alone it was barely worth it based on the current EU customer base we have. We’d also be very happy if one of our competitors started investing in the EU market. It’s worth about…

Or just ignore it, take on EU customers anyway, deal with the risk.

An option that I see a lot of companies taking, we considered it, but decided it wasn’t worth it. I personally know of a few companies that have decided to blatantly ignore it until they see how offshore enforcement works out. If it ends up being favourable, it’s a strategy we may adopt.

Re: GDPR: Don't Panic

#524

I personally am not hysterical about any of this, I just am concerned for the citizens of the EU while living under this law. My main issue with the GDPR is that articles and supporters are constantly thinking in terms of "business" and not in terms of other services, and also not thinking in terms of long term impact. For instance, I run a small community website (~30 people). I receive no income, and I know everyon…

You make a great point. GDPR seems to be a very big headache for small hobbyist-type Internet communities.

Re: GDPR: Don't Panic

#525

Earlier quoted context omitted.

In principle I might agree with you, however the EU has a long history of striking a fair balance between consumer rights and commercial interests. There is no point, in history, of the EU doing anything remotely like you've described. Which actually gives me more faith in the GDPR than legislation in a corrupt ecosystem as corrupt individuals will find a way to warp legislation in their favor anyway. So yes, I do tr…

Related to this, there is a difference in culture that may had add to the fear for people running SMEs outside of Europe. I am talking about a difference in the culture of fines, at least at the local level of government based on my personal experience. When I lived in Canada (and the US briefly) it was common for me to get fined for various trivial offences. I used to joke I should have a fine budget, or at least fi…

> Now since being back in the UK for six years I've not received a single fine, had any interaction with the police or courts.

I'm 26, have always been Canadian and I never seen what you talk about there. It's disturbing that you had this experience.

The only fine I ever heard someone get where relative to the road and were mostly parking and speed tickets. Even then, I also don't know anyone that doesn't drive 120 kph on a 100 kph road and about the parking, the signs are pretty self explanatory (though they can become pretty complicated where there's more than one).

If you consider that you follow what any signs, well that would means you shouldn't get any of theses fines. Theses fines are also defined and you know what you risk if you don't follow the signs.

Now say the same about GDPR... pretty harder I would say.

People drive at 120 on a 100 road and that's alright even though cars kills thousand each year, much more than keeping your shipping information in a database, yet you risk a much bigger fine for keeping that information without following the "signs".

Re: GDPR: Don't Panic

#526

As a solo business owner based in the US, I’ve been spending the last couple weeks learning about GDPR and getting compliant. While it has not been a fun process, I do think in general the regulation is quite reasonable and overall good for the world in general. So far, GDPR compliance has not cost me any money, only time. There are three problems however that I have with GDPR and I’d love to hear how other small non…

> has not cost me any money, only time

It sounds like you don't value your time. In my universe (software development), time is money.

Re: GDPR: Don't Panic

#527

Earlier quoted context omitted.

A lot of companies won't hire you if you have a criminal record of any kind. Some won't even hire you if you have any record of arrest, regardless of conviction. Which fraternity?

If the court seals the record its nearly impossible for anyone but government agencies to discover

wasn't there just a story about background check startups finding these records and using them?

Re: GDPR: Don't Panic

#528

Earlier quoted context omitted.

A lot of companies won't hire you if you have a criminal record of any kind. Some won't even hire you if you have any record of arrest, regardless of conviction. Which fraternity?

If the court seals the record its nearly impossible for anyone but government agencies to discover

Yes, but that costs money and not all states do it. My state has a fully searchable arrest database with mugshots.

Re: GDPR: Don't Panic

#529

Earlier quoted context omitted.

We ran the numbers on how much it would cost to establish compliance, and with that alone it was barley worth it based on the current EU customer base we have. We also considered all the additional liability we’d be taking on, and with that alone it was barely worth it based on the current EU customer base we have. We’d also be very happy if one of our competitors started investing in the EU market. It’s worth about…

>(and investing in compliance with European - absolutely not international - regulations) Did you think about this before typing? Clue: how many countries does an EU-wide law directly apply to? One? Or many?

You are playing on semantics, anyway EU regulations apply to no country as it’s enforced by each member of the union, not by EU itself.

Re: GDPR: Don't Panic

#530
How can I be non-compliant with GDPR? If I could care less about it, is it enough for me to do nothing? Should I expect that European users should find out themselves that they my website is not GDPR-compliant? Or I must actively ban EU IPs?
Post reply on HN