Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

531–540 of 833 posts

Re: GDPR: Don't Panic

#531

Earlier quoted context omitted.

You are advertising that your handling of personal data is so haphazard that GDPR compliance would be expensive. You are admitting that you aren't good enough for the EU, and therefore that you aren't very good in general at whatever you do. I expect that, at least in some obviously global markets like most e-commerce, GDPR compliance (as opposed to throwing the towel like you) will be treated like a certification of…

I’m sorry, but this is simply the naive opinion of somebody that has clearly never had to deal with compliance before on a meaningful level. My customers are all happy with my privacy policy, and not a single one outside of the EU has expressed any interest at all in the GDPR. We are actually compliant with a majority of the regulation, however there are some areas where we would have to re-architect to gain full com…

Right now we are going through a federal audit. We sell only to US orgs, but also have a social media platform.

Because our social media platform is open to all, we are addressing adhering to the GDPR. In spirit, we already do, but they want what amounts to 5 documents how we use metrics and user data.

(Edit: we use metrics only in a '20 new people signed up'. We treat all data as federal confidential data. We also abide by deletion requests - immediately all user data is zeroed out, and a script overnight removes the zeroed fields. If it should not have been entered, we also will nuke users on backups too.)

If you're doing things respectfully and the right way, the GDPR is a nuisance. If you were hoovering anything and everything, you're in for a bad time.

And given your comments above, I'd put you in the company of "Hoover, Dyson, and Electrolux".

Edit: > "My customers are all happy with my privacy policy,"

Do they have a choice, aside to never use your stuff? If do you force acceptance of the 'privacy policy' on usage of your service? If you, that is in direct violation of the GDPR.

Hope you never want to consider European citizens as a customer. Building in this respect is cheap, but is expensive if you ignore now.

Think of this as "California Emissions". Eventually the US will adopt, even if in defacto. Might as well be on the right side of the fence.

Re: GDPR: Don't Panic

#532

Earlier quoted context omitted.

Also any Americans reading “we can trust X” will likely get a good laugh out of this. It is irresponsible not to assume that if the law is written a certain way then at some point, the law can (and likely will) be enforced that way when it suits the government.

> It is irresponsible not to assume that if the law is written a certain way then at some point, the law can (and likely will) be enforced that way when it suits the government. With the caveat that "the law" in this case isn't just the GDPR, it's the entirety of EU case law. GDPR exists in a particular legal context.

I get the impression I am misunderstanding EU law (not necessarily a surprise) when folks say things like "Civil law vs. Common Law" or "legal context."

If a law is on the books, it can be enforced in the EU, right? I understand there is precedent but precedent is not law, it's merely the common understanding of that law in that particular context. Precedent is overturned all the time (not to mention ignored when convenient), as it should be.

Is there a critical difference here that I am not understanding? Perhaps it has to do with the fact that the EU is not a state, but a high level guiding body for a number of states?

Re: GDPR: Don't Panic

#533
post #400
post #356

Earlier quoted context omitted.

There's a lot of American libertarians that believe government is intrinsically bad, for some reason. And also a monolith; they don't see any difference between bits of government, different branches, different types of enforcement, and so on. They're very loath to admit that it takes a certain minimum amount of structure to keep the roads open and the lights on.

> to keep the roads open and the lights on I'd cynically add: > and to prevent people from killing and robbing each other each day There's a reason we have Wikipedia articles like this one: https://en.wikipedia.org/wiki/Highwayman

I do agree with the power of government to break the prisoners dilemma regarding to public works, but not that they have that much control over people's behavior.

The tendency of people to follow laws has shown little relation to blunt enforcement. It has to do with peoples tendency to follow norms.

https://en.wikipedia.org/wiki/Group_cohesiveness

Re: GDPR: Don't Panic

#534

Earlier quoted context omitted.

>(and investing in compliance with European - absolutely not international - regulations) Did you think about this before typing? Clue: how many countries does an EU-wide law directly apply to? One? Or many?

You are playing on semantics, anyway EU regulations apply to no country as it’s enforced by each member of the union, not by EU itself.

The GDPR regulation directly applies in all member states, and does not need individual states to do anything at all to enact it. If national courts decline to enforce it then it can escalate to the Eu courts.

It is also international in that it applies to EU citizen date no matter which country it is held or processed in.

Re: GDPR: Don't Panic

#535
post #525

Earlier quoted context omitted.

Related to this, there is a difference in culture that may had add to the fear for people running SMEs outside of Europe. I am talking about a difference in the culture of fines, at least at the local level of government based on my personal experience. When I lived in Canada (and the US briefly) it was common for me to get fined for various trivial offences. I used to joke I should have a fine budget, or at least fi…

> Now since being back in the UK for six years I've not received a single fine, had any interaction with the police or courts. I'm 26, have always been Canadian and I never seen what you talk about there. It's disturbing that you had this experience. The only fine I ever heard someone get where relative to the road and were mostly parking and speed tickets. Even then, I also don't know anyone that doesn't drive 120 k…

Yes, literally nobody has die for misuse of privacy data, and now you can go to jail over it.

Re: GDPR: Don't Panic

#536
post #476

Earlier quoted context omitted.

Did you actually look into the GDPR before jumping to these conclusions about the effects on your business? For example, if you have a legitimate need for user data (e.g. "I need to collect it and store it to comply with other laws") then the GDPR does not apply. This is very plainly laid out for those that care to actually inform themselves.

> Did you actually look into the GDPR before jumping to these conclusions about the effects on your business? The fact that I have to look into the GDPR already proves my conclusion to be true. I fully expect there to be few if any issues, but I still need to verify against the regulation, which is thousands of lines of text. I can't just refer to "salvar on hackernews" saying it's "legitimate" if it's for legal comp…

Yes, you need to look into regulations to make sure you're complying with them. I really hope that this is not news to you if you are running a business or service.

Re: GDPR: Don't Panic

#537

How can I be non-compliant with GDPR? If I could care less about it, is it enough for me to do nothing? Should I expect that European users should find out themselves that they my website is not GDPR-compliant? Or I must actively ban EU IPs?

If you actively choose not to pursue compliance, you should make it clear in your own privacy policy that the site is not for use by EU/EEA citizens and also use IP geolocation to block their requests.

Re: GDPR: Don't Panic

#538

Earlier quoted context omitted.

Same here. EU makes up such a small amount of or customer base, and EU customers spend far less money with us. Which is generally true in most industries, US consumers spend far more than consumers anywhere else in the world. If we ever choose to enter the EU again, it will be a careful and deliberate choice, and will likely only ever happen if our growth slows in other regions.

As a formerly European person running internet companies in the USA this baffles me. Why the teeth gnashing over being told not to spy on your users?

This argument makes about as much sense as "if you have nothing to hide, you have nothing to fear" in support of surveillance laws. Presumption of guilt is a terrible rule to live by.

Re: GDPR: Don't Panic

#539
post #392
post #387

It ain't hysteria if you're in Germany, and a private individual or a nonprofit (e.V.). Due to specialities of German law third parties can serve you legal writs for hundreds or thousands of EURos. Which is why I'm shutting down these 20 domains running HTTP/SMTP services I'm hosting in less than a week, and wait until the smoke clears.

GDPR doesn't apply to personal projects unless those are commercial projects.

I've read contradictory claims. Another commenter mentioned changes to their personal blog to be compliant.

Re: GDPR: Don't Panic

#540

Earlier quoted context omitted.

You are playing on semantics, anyway EU regulations apply to no country as it’s enforced by each member of the union, not by EU itself.

The GDPR regulation directly applies in all member states, and does not need individual states to do anything at all to enact it. If national courts decline to enforce it then it can escalate to the Eu courts. It is also international in that it applies to EU citizen date no matter which country it is held or processed in.

That’s not true. It’s implemented by each data regulation agencies in each country. The CNIL in France for example. There is no EU GDPR agency.
Post reply on HN