Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

541–550 of 833 posts

Re: GDPR: Don't Panic

#541
This is what pisses me off the most about all the hysteria and whining:

"The law has been in effect for over two years at this point, and the DPD, the European Data Protection Directive has been in effect for over two decades. So no, this law was not sprung on anybody, though it is very well possible that you only became aware of it a few weeks or months (or days?) ago. If that’s the case do not panic, you too will most likely be fine."

Nevermind the fact that the underlying privacy laws are much older, and so many practices were already essentially illegal but went unchallenged so far.

Re: GDPR: Don't Panic

#542

I personally am not hysterical about any of this, I just am concerned for the citizens of the EU while living under this law. My main issue with the GDPR is that articles and supporters are constantly thinking in terms of "business" and not in terms of other services, and also not thinking in terms of long term impact. For instance, I run a small community website (~30 people). I receive no income, and I know everyon…

> For instance, I run a small community website (~30 people). I receive no income, and I know everyone involved

You may be able to ignore GDPR compliance in your situation, as per article 2:

> This Regulation does not apply to the processing of personal data: [...] by a natural person in the course of a purely personal or household activity; [...]

There is some more information in recital 18, that says

> This Regulation does not apply to the processing of personal data by a natural person in the course of a purely personal or household activity and thus with no connection to a professional or commercial activity.

So if you're not making money, and you're not established as a business you should be okay.

If you have any doubts or concerns, become compliant or ban all EU/EEA users.

Re: GDPR: Don't Panic

#543

What is stopping competitors from burying each other in legal work? Just start commenting names and addresses on various pages and submit complaints

What does competitors stop doing that now? No business is 100% compliant in any law. If they want they can just for the sake of it bury you in legal work already.

See Google vs Oracle. Apple vs Google.

Re: GDPR: Don't Panic

#544

I don't think it's really that simple. especially the deletion requirements. There are just so many IT systems that really don't support deletion. An absolute worst case I can imagine is GitHub being asked to delete an account which had commits in multiple large projects. Are they going to alter those projects source code?

This is already a “solved problem” though. If you post copyrighted material to Github, Github will have to remove it. If you’re posting users information to a public repo, then you fully deserve whatever impacts you’ll face when you have to delete it.

> If you’re posting users information to a public repo

Like their name and email address in every commit they submit?

I've already seen a notice from GitLab requiring me to consent to waive my rights to have that info deleted if, e.g. I were to contribute to the GitLab open source project. But I'm not sure that that's even enough for GDPR.

Re: GDPR: Don't Panic

#545

The GDPR gets so much hate because it hits so many businesses where it hurts: data. GDPR "simply" gives you guidelines on how you can handle data from people within the EU. And that that data cannot be handled so liberally as it has been before. Of course that's annoying from a business perspective, but from an individuals privacy perspective, it's fantastic.

What’s fantastic about it? Worst abusers of privacy are goverments, and nothing has been done in this law to restrict it.

Re: GDPR: Don't Panic

#546

GDPR puts into jeopardy the business model that almost every consumer internet business has run on, post internet bubble: advertising. That's what is at jeopardy here and nobody is willing to just say it. Don't agree with the concept of tracking users to serve them ads? Great, make the case that GDPR ends the scourge of advertising subsidized applications as services. Let's not ignore it though. The reality is, a lot…

> we need to agree that the bulk of the last 20 years of startups business models are broken

I agree.

If a startup is build on selling my data, I am more willing to pay a fee then to have them sell my data.

If we could go back to WhatsApp having a fee instead of Facebook using and selling my (meta)data, I would switch anytime. If Telegram starts raising a fee for using their messenger without anybody reading my messenges/location/... I am all in.

Re: GDPR: Don't Panic

#547

Earlier quoted context omitted.

I think it gets "hate" from people who don't have much data but they still have to implement all the requirements, which go beyond than their own data storage. Ad-supported websites are probably the most common case here, even if the sites don't store any data themselves.

And that is a good thing. This >23 different trackers and adservers just to read crappy news content BS is so nice to be shaken. I really love the GDPR for just making the life for such business models way harder. Implementing data, analytics, tracking and stuff in a way that is compliant with GDPR (or its local equivalents) is doable and from an architectural point of view even interesting imho. I love building GDPR…

Don’t go to this kind of websites then. There is nothing warranting you to kill them though.

Re: GDPR: Don't Panic

#548

This is what pisses me off the most about all the hysteria and whining: " The law has been in effect for over two years at this point, and the DPD, the European Data Protection Directive has been in effect for over two decades. So no, this law was not sprung on anybody, though it is very well possible that you only became aware of it a few weeks or months (or days?) ago. If that’s the case do not panic, you too will…

> > The law has been in effect for over two years at this point

So what's this whole thing that's going to happen soon? It's going into double effect or something?

Re: GDPR: Don't Panic

#549

This is what pisses me off the most about all the hysteria and whining: " The law has been in effect for over two years at this point, and the DPD, the European Data Protection Directive has been in effect for over two decades. So no, this law was not sprung on anybody, though it is very well possible that you only became aware of it a few weeks or months (or days?) ago. If that’s the case do not panic, you too will…

Because nobody gave a duck, because there was no fine (or they were laughable).

Now that we have a single law for a 500 million customer market with a substantial fine, things start to shift to the better.

Re: GDPR: Don't Panic

#550

As a solo business owner based in the US, I’ve been spending the last couple weeks learning about GDPR and getting compliant. While it has not been a fun process, I do think in general the regulation is quite reasonable and overall good for the world in general. So far, GDPR compliance has not cost me any money, only time. There are three problems however that I have with GDPR and I’d love to hear how other small non…

First of IANAL, I'm a European citizen within IT that has to deal with GDPR in my professional role. I believe there is a lot of hysteria and FUD around GDPR. Anyway, this is how I would handle your problems.

1. In the same article[1] that you reference, the following paragraph might apply to your business: >27.2 The obligation laid down in paragraph 1 of this Article shall not apply to: >processing which is occasional, does not include, on a large scale, processing of special categories of data as referred to in Article 9(1) I would ignore it for now. If any supervising authorities would contact you regarding compliance issues, talk to an expert.

2. This is if you use Consent as the legal basis for collecting the data. I have seen a few business use 6.1.f [2] (legitimate interests) as their legal basis, which has other issues like the weight test of interests not being tested in court, yet. The Article 29 Data Protection Working Party have released opinions on how 'legitimate interests' should be used [3]. However, there are other laws about marketing that could apply on a country per country basis. If you select the consent route, a double opt in with possibility to opt out at anytime that should be sufficient as long as you document the text for the opt-in's and record it together with the date&time of the opt-in. Oh, and you don't make the consent conditional on getting your goods/services. I can recommend the Article 29 WP guidelines on consent[4] for extended reading. It sounds like your current process is enough or requires very little tweaking, I would keep it as is.

3. I have not run a consent campaign. I have run information campaigns about our users rights with links to required documentation and they have been appreciated. I would not run a consent campaign as I believe your consent should be good enough based on the process mentioned above.

Hope this helps! - [1] https://gdpr-info.eu/art-27-gdpr/ [2] https://gdpr-info.eu/art-6-gdpr/ [3] http://ec.europa.eu/justice/article-29/documentation/opinion... [4] https://iapp.org/media/pdf/resource_center/20180416_Article2...

Post reply on HN