Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

551–560 of 833 posts

Re: GDPR: Don't Panic

#551
post #414
post #364

Earlier quoted context omitted.

If you are fined 10k-100k you have the typical problem of whether it is worth fighting.. But you are supporting the argument that you could be illegally (according to article 83) fined 4 million euros as a first offence because a regulator wants to be disproportionate and set an example with your small company and then have costs of 10-100k to throw out an obvious case, but it wouldn't be worth it?

It's worth it but it bankrupts you. No customers, no investors, and all your cash gone before your appeal is heard. Block all EU traffic. Just cut the transatlantic cables.

Maybe you should list all of the possible cases that could be initiated against you as a business owner in the US and which ones you can and can't guard against before you worry about that cable.

Re: GDPR: Don't Panic

#552

This is what pisses me off the most about all the hysteria and whining: " The law has been in effect for over two years at this point, and the DPD, the European Data Protection Directive has been in effect for over two decades. So no, this law was not sprung on anybody, though it is very well possible that you only became aware of it a few weeks or months (or days?) ago. If that’s the case do not panic, you too will…

> > The law has been in effect for over two years at this point So what's this whole thing that's going to happen soon? It's going into double effect or something?

The law was made public two years ago, to give companies time to get compliant. It actually goes into effect next friday.

Re: GDPR: Don't Panic

#553
post #386

Earlier quoted context omitted.

I don't think that's fair. I rather think it gets a lot of hate because it leaves a lot to the discretion of the regulators. Overall, the SMEs I talk to don't have a problem with regulating data (most think it will pop the gangrenous ad-tech bubble). It's the lack of predictability that bothers them.

The "lack of predictability" is a good thing. "You're making efforts to comply with the regulations, but could you have a look at how you're storing this and that?" vs "You're not compliant with the regulation so we have to impose a fine" Are you really saying you'd prefer the second?

It is the converse of the second that worries people. Look at an ironically US example of Slingbox forwarding TV antennas to other locations in a 1:1 fashion specifically to not count as rebroadcasting. That took a Supreme Court case and much legal maneuvering to sink something that was legal because they didn't like it.

People are rightfully worried about "you followed the law completely but we don't like it so massive fines!".

Re: GDPR: Don't Panic

#554

Earlier quoted context omitted.

I’m sorry, but this is simply the naive opinion of somebody that has clearly never had to deal with compliance before on a meaningful level. My customers are all happy with my privacy policy, and not a single one outside of the EU has expressed any interest at all in the GDPR. We are actually compliant with a majority of the regulation, however there are some areas where we would have to re-architect to gain full com…

Right now we are going through a federal audit. We sell only to US orgs, but also have a social media platform. Because our social media platform is open to all, we are addressing adhering to the GDPR. In spirit, we already do, but they want what amounts to 5 documents how we use metrics and user data. (Edit: we use metrics only in a '20 new people signed up'. We treat all data as federal confidential data. We also a…

So because you don’t have many in-scope systems, you believe that the cost of compliance is going to be the same for every company in the world? And what did I say that gave the impression that I don’t respect my users or their data?

Our application is a financial one, so I’d say it’s reasonable to assume that it ends up with a lot more in-scope PII than yours does.

In spirit, we also comply with almost all of the GDPR. However, some of its undefined edge cases prevent us from fully complying with it without an expensive re-architecture project, and re-implementation of some of our toolset. The areas we don’t comply with are incredibly minor, and I’ve seen some people arguing that we’d fall within the GDPRs limits of flexibility. However, that’s not how we manage risk. No matter how confident we were, being wrong could potentially end our business with fines.

As I have said repeatedly, for many small to medium sized businesses that don’t have many EU customers, there is simply no reason to implement GDPR at all. The costs can be quite high, and the risk of getting it wrong is enormous and not survivable. This is one of the many unintended (although entirely expectable) side effects of the regulation. All you’re trying to do is spread FUD.

Re: GDPR: Don't Panic

#555
post #193

Earlier quoted context omitted.

Example: How do you ask user for a permission to log access logs (which contain IP address) in the server, so that you can detect spam, ddos and other attacks? How do you store that consent information and what do you do if user doesn't consent? What do you do if user connecting from given IP address wants you to send him data you have collected about him. If people share IP addresses how do you know which log data i…

> How do you ask user for a permission Why do you think permission is required?

Because that is personal information that is being stored and processed.

Re: GDPR: Don't Panic

#556

Earlier quoted context omitted.

so you say. if you don’t have strong processes to make sure that is true, it isn’t true. gdpr is mostly about ensuring you have such processes. if you can’t do things such as tell the user what data you have, and delete it, you do not have a great policy. methinks you need some advice from better counsel. i bet that you are closer to compliant than you think.

Do you actually think the only way to respect users privacy is to comply with GDPR? That is an absurd and narrow minded opinion. Do you also actually believe that the entire regulation is reflected in your two line comment? Listen, you’ve said higher up the thread that you are plan to spread FUD about all companies that don’t comply with GDPR as a marketing strategy for your own product. I don’t see how anybody here…

> That’s not true, and for many companies this is just a simple business decision.

But likely based on incorrect advice.

You haven't said why you think your company isn't compliant with GDPR, and it's possible your company is compliant with GDPR, or would require only minor tweaks to privacy policies to make it compliant.

Re: GDPR: Don't Panic

#557
post #17

This is just an author wishlist and not the reality. I especially find the "clearing house" fantasy amusing. How he thinks this house of bureaucrats will be able to judge that John Does complaint has any merit?

I recognized your user name from the other thread ( https://news.ycombinator.com/item?id=17095217 ), it looks like you've made up your mind (to the point where your comments where ridiculous enough to be deleted) and no amount of argument will even get you to consider any other options. Why don't you tell us how you really feel?

I am only trying to understand why people feel so easy about it. I read hundreds of articles on the topic and nobody really has a clue what is going to happen. That my comments were deemed ridiculous and deleted is the symptom how crazy this whole thing is.

Re: GDPR: Don't Panic

#558
post #64

Earlier quoted context omitted.

Not an alternative - but the only obvious defence is to do the right thing, and delete data as soon as you have completed processing. e.g. delete those interview notes the second you have declined the candidate.

That's ridiculous. Has anyone in this thread actually ever run a recruiting operation? I have. There's no way we will be deleting interview notes the moment a candidate is rejected. For one, we have to be able to prove later that we didn't reject based on grounds of discrimination (other regulations). But you also need the ability to review what your interviewers are doing to ensure consistency and quality of assessm…

> There's no way we will be deleting interview notes the moment a candidate is rejected. For one, we have to be able to prove later that we didn't reject based on grounds of discrimination (other regulations).

The fun of red tape. You will be violating one or the other regulation, that’s the beauty of it.

Re: GDPR: Don't Panic

#559
post #200

Earlier quoted context omitted.

So how do they know if the response with the data a user requests, are all we've got about them, and if indeed where stored the proper way?

As far as I know, you pay for an audit yourself, and then you send them the results.

How difficult would be to pay auditor to close their eyes? Do you need another audit?

Re: GDPR: Don't Panic

#560

Earlier quoted context omitted.

I suspect it wouldn’t work in the US. Principles based regulation requires some level of concensus on principles. We don’t have that in the US. Polarization breeds rules worship because you don’t trust the other people to use their discretion. Consider, for example, how every major social issue devolves into a Constitutional litigation. Whereas in Europe people just vote on stuff. And as to regulatory approaches I th…

Oh totally agree. Just think about the DMV. The people who work there cite the law word with zero discretion. Most US companies are like that as well. It's quite dystopian. Well lets say it wouldn't work with the current ruling class mindset where everyone they employ is stupid and unable to think critically.

It depends on where you are. In places like Oregon, the DMV is a friendly place full of smiles where expiration dates can slip a few days and you don't have to change your hairstyle for your ID photo.
Post reply on HN