Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

571–580 of 833 posts

Re: GDPR: Don't Panic

#571
post #454

Earlier quoted context omitted.

You've misread the legislation. The maximum sentences you're referring to are for summary convictions at a magistrates court. Possession of a controlled substance is an each-way offence which can be tried at either a magistrates or crown court. There is a higher maximum sentence if your offence is tried at a crown court, which is listed in schedule 4, namely "5 years or a fine, or both".

But that law has to be read in conjunction with others, which set out when trial is at magistrates or crown court; and what the sentencing guidance is. The courts must follow the sentencing council guidelines unless it's in the public interest not to do so. https://www.sentencingcouncil.org.uk/wp-content/uploads/Drug... The starting point is 100% of weekly income; the range is 75% to 125% of weekly income. > Band B 1…

Judges don't have to adhere to guidelines as these are only guidelines. I have seen couple of cases where people were punished severely for something rather minor. Only thing you can do is to complaint about the judging.

Re: GDPR: Don't Panic

#572

Earlier quoted context omitted.

As a formerly European person running internet companies in the USA this baffles me. Why the teeth gnashing over being told not to spy on your users?

We’ve got a great privacy policy, and don’t abuse our customers data in any way. However compliance would be very expensive for us, largely due to some of our early architecture decisions. The liability is also insane, and we don’t want anything to do with it. When we looked at how little our EU customers were worth to us, it was a very easy decision to simply abandon them.

>compliance would be very expensive for us

Care to expand on this? What would you need to do that you weren't doing already?

Re: GDPR: Don't Panic

#573

Earlier quoted context omitted.

What you dub principles-based regulation others call trust-based regulation, or randomly-enforced regulation, or we-know-it-when-we-see-it-based regulation. Some don't appreciate this type of regulation. I think the unfortunate thing is that, when the previous/existing incarnations of these protection laws were/remain unenforced, many assumed it was because of lack of "teeth". But those of us familiar with how these…

And rules-based regulation means you commit 3 felonies per day https://www.wsj.com/articles/SB10001424052748704471504574438...

That's a myth, and the article you posted is an op-ed piece with no substance to back up the claim it makes.

Re: GDPR: Don't Panic

#574

Earlier quoted context omitted.

And rules-based regulation means you commit 3 felonies per day https://www.wsj.com/articles/SB10001424052748704471504574438...

Going on a bit of a tangent here, I am becoming concerned with how we discuss these things. You're completely either for or against it. And if you're against one way you are automatically for the other. If you think one thing is bad, obviously you need to be corrected that other thing is bad too. And then you'll get extreme examples showing it. Call it whataboutism, appeal to emotion, whatever. Every time these GDPR…

I think your tangent is merited and unfortunately there seems to be a lot of polarizing comments (I might have done a couple, but there are some that really go over the top in either direction, like "hiring a lawyer to be your DPO is trivial" or people spreading FUD and saying how they will have to shut access from the EU to their personal site, etc.)

But in essence people are missing the bigger context.

Re: GDPR: Don't Panic

#575

I'm an attorney who's spent the last year or so working on GDPR compliance for a US SaaS provider some of whose clients have EU employees. My understanding is that it's true that EU enforcement is more in the spirit of "how can we get you compliant?" before doling out fines (vs. the US where it can be more "let's make an example of this company by hitting them with a big fine" and scaring others into compliance). I a…

The Honda case actually seems pretty reasonable to fine - Honda had an issue where consent from dealer events and other sources wasn't correctly recorded. So they have a large list of emails, where consent falls into three categories:

* Person did not consent, they left the form blank

* Person consented, but it was not recorded

* Person actively denied consent ( wrote "no")

Honda then sent commercial email to this set of users, to "confirm" their preferences. In my view, that's not reasonable - if I leave a "would you like to receive email" item in a form blank, that is not permission to send me email.

Re: GDPR: Don't Panic

#576
post #48

This doesn't consider some factors that dictate how strong any company will experience their firehose of GDPR requests to be: - how incentivised people are to make GDPR subject access requests of the company (how angry, confused, hostile curious they are) - how easy it is for them to make requests (entirely manual vs. online service) - wildcard factors (internet flash mobs bent on vengeance against a corporate) There…

> For example, unsuccessful candidates applying for a job at a company could forward their rejection email to a bot. The bot parses the details and fires a GDPR access request in to the HR department. The candidate gets back a formatted dump by email of all sorts of recruitment data, including interview notes, etc. There are obvious ways to monetise a service like this, hence incentive for someone to do it. Recruitment at a large company means engaging with thousands of people and then rejecting them. It is natural for people to have bruised feelings, and also to be curious about why they were not hired. A GDPR button lets them indulge their curiousity and start digging in to interview notes etc.

Huh. So, you’re saying a side effect of GDPR is a radical increase in recruitment/hiring transparency. As if that was a bad thing (clearly, it would be a shift in the capital/labor power assymetry in favor of labor, but I'm not seeing how that's bad.)

Re: GDPR: Don't Panic

#577
post #573

Earlier quoted context omitted.

And rules-based regulation means you commit 3 felonies per day https://www.wsj.com/articles/SB10001424052748704471504574438...

That's a myth, and the article you posted is an op-ed piece with no substance to back up the claim it makes.

The source is the book of that name, written by an US lawyer. There's some discussion and better sources on Google.

Re: GDPR: Don't Panic

#578
post #317

Earlier quoted context omitted.

In England and Wales, you could be fined £10^99 for having a crumb of cannabis in your pocket. There is nothing - and I do mean nothing - written in the Misuse of Drugs Act that requires any warnings of any kind, or places any limits on fines. The maximum sentence for possession of a Class B controlled substance is five years imprisonment and an unlimited fine. Period. A fine larger than the number of atoms in the un…

Yes, but the point I'm trying to get across to people is that there's a general legal requirement that the legal and administrative systems be proportionate, even if it's not incorporated by explicit reference in every piece of legslative text. (I can't lay hands on it at the moment but there are clear guidelines to UK judges on what constitutes reasonable fines for offences, such that it should be feasible for the p…

UK judges don't have to follow the guidelines - these are just guidelines, but judge can use his/hers own discretion within the law. In case of drugs some judges expose almost psychotic hatred towards drug users and can deal punishment outside of the guidelines.

Re: GDPR: Don't Panic

#579
post #386

Earlier quoted context omitted.

The "lack of predictability" is a good thing. "You're making efforts to comply with the regulations, but could you have a look at how you're storing this and that?" vs "You're not compliant with the regulation so we have to impose a fine" Are you really saying you'd prefer the second?

It is the converse of the second that worries people. Look at an ironically US example of Slingbox forwarding TV antennas to other locations in a 1:1 fashion specifically to not count as rebroadcasting. That took a Supreme Court case and much legal maneuvering to sink something that was legal because they didn't like it. People are rightfully worried about "you followed the law completely but we don't like it so mass…

> People are rightfully worried about "you followed the law completely but we don't like it so massive fines!"

That seems largely independent of how precise/vague the laws are, if you're expecting the enforcing party to find a way to get you regardless.

The 'defence' here seems to be that you can make a decent argument that you've taken appropriate measures to conform with your [reasonable] interpretation of the rules.

The regulator can object (and possibly penalise you) if they think you're not acting in good faith, or you have a grossly unreasonable interpretation of those rules. You can object to an unfair interpretation of the rules by the regulator as well.

Either way, if The Powers That Be want you nailed to a wall, they'll find a way, this particular regulation or not.

Re: GDPR: Don't Panic

#580

The GDPR gets so much hate because it hits so many businesses where it hurts: data. GDPR "simply" gives you guidelines on how you can handle data from people within the EU. And that that data cannot be handled so liberally as it has been before. Of course that's annoying from a business perspective, but from an individuals privacy perspective, it's fantastic.

It's not that it's annoying, it's that I literally cannot answer "are we GDPR compliant?". If you search for GDPR IP address, you get a ton of different opinions. Do I need to sanitize logs? How does that fit in with the requirements for security compliance we are also subject to?

At the end of the day, I am the one person who has to answer that question/is responsible for being GDPR compliant. I've spent hours doing research, figuring out what we need to do and implementing it -- and it's a hollow victory because even though I've said yes and have 100s of articles/white papers/opinions that back up the decisions I've made, the real answer is still "I don't know".

And I absolutely know I'm not alone in this. I got GDPR compliance dropped on my lap because I did security compliance -- if you contrast NIST 800-53/800-171 against GDPR you'll see why people are pissed off. One has clear guidelines with enough room for evolving best practices written by obviously competent/experienced professionals, the other is written as basically "we'll know it when we see it".

Post reply on HN