Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

581–590 of 833 posts

Re: GDPR: Don't Panic

#581

I'm an attorney who's spent the last year or so working on GDPR compliance for a US SaaS provider some of whose clients have EU employees. My understanding is that it's true that EU enforcement is more in the spirit of "how can we get you compliant?" before doling out fines (vs. the US where it can be more "let's make an example of this company by hitting them with a big fine" and scaring others into compliance). I a…

From the PDF you linked to:

"This e-mail was sent to those individuals on the database where no “opt in” or “opt out” information was held"

Sounds like they were basically on a fishing expedition - if the individuals hadn't explicitly opted in, Honda shouldn't be sending them emails.

Re: GDPR: Don't Panic

#582

Earlier quoted context omitted.

In principle I might agree with you, however the EU has a long history of striking a fair balance between consumer rights and commercial interests. There is no point, in history, of the EU doing anything remotely like you've described. Which actually gives me more faith in the GDPR than legislation in a corrupt ecosystem as corrupt individuals will find a way to warp legislation in their favor anyway. So yes, I do tr…

Related to this, there is a difference in culture that may had add to the fear for people running SMEs outside of Europe. I am talking about a difference in the culture of fines, at least at the local level of government based on my personal experience. When I lived in Canada (and the US briefly) it was common for me to get fined for various trivial offences. I used to joke I should have a fine budget, or at least fi…

I think UK is a special case here. In other EU countries it is not uncommon for corrupt civil servants to drown companies in fines to the point of bankruptcy.

Re: GDPR: Don't Panic

#583

The GDPR gets so much hate because it hits so many businesses where it hurts: data. GDPR "simply" gives you guidelines on how you can handle data from people within the EU. And that that data cannot be handled so liberally as it has been before. Of course that's annoying from a business perspective, but from an individuals privacy perspective, it's fantastic.

> Of course that's annoying from a business perspective, but from an individuals privacy perspective, it's fantastic.

So many people are pro-privacy until it affects their bottom line.

Re: GDPR: Don't Panic

#584

Earlier quoted context omitted.

This is already a “solved problem” though. If you post copyrighted material to Github, Github will have to remove it. If you’re posting users information to a public repo, then you fully deserve whatever impacts you’ll face when you have to delete it.

> If you’re posting users information to a public repo Like their name and email address in every commit they submit? I've already seen a notice from GitLab requiring me to consent to waive my rights to have that info deleted if, e.g. I were to contribute to the GitLab open source project. But I'm not sure that that's even enough for GDPR.

The waiver is only one aspect of it. Waiver only applies when consent is required. Article 6 of GDPR also allows for the use of personal information when "processing is necessary for the performance of a contract to which the data subject is party..." Consent is not required when it is a necessary part of performance under a contract. GitLab's updated terms state that as part of the agreement to voluntarily contribute to GitLab projects, contributors acknowledge and agree that their personal information will become part of the repository as part of the Git functionality. Therefore, their personal information will not be deleted and will remain in the repository so as not to impact the code base. This only applies to those who contribute to GitLab projects. This does not apply to general use of the software. There is still much that is unclear regarding GDPR but we are doing our best to comply and protect individuals' privacy. An important function of this waiver and acknowledgement is to provide transparency to our contributors. If an individual does not want their information to be maintained, they have the option not to contribute.

Re: GDPR: Don't Panic

#585

Earlier quoted context omitted.

As a formerly European person running internet companies in the USA this baffles me. Why the teeth gnashing over being told not to spy on your users?

We’ve got a great privacy policy, and don’t abuse our customers data in any way. However compliance would be very expensive for us, largely due to some of our early architecture decisions. The liability is also insane, and we don’t want anything to do with it. When we looked at how little our EU customers were worth to us, it was a very easy decision to simply abandon them.

If you are already compliant with your great privacy policy, what are some specific things that you find too expensive to be worth it? All I read from GDPR detractors are vague hand wavey claims of “compliance stuff” being expensive. I’m obv not a professional compliance expert so ELI5.

Re: GDPR: Don't Panic

#586
post #405
post #105

Earlier quoted context omitted.

> and also to be curious about why they were not hired. A GDPR button lets them indulge their curiousity and start digging in to interview notes etc. If your company can not show the candidates why they were not hired, you are doing a very bad job. Are you discriminating against protected classes? Are you rude or offensive in your comments? Then, stop doing it. That will be a very good side-effect of this situation.…

> If your company can not show the candidates why they were not hired, you are doing a very bad job. You sound like you've never had to deal with telling a candidate they weren't chosen for a position. There's a reason rejection letters are usually canned responses - it's not that HR teams are unanimously evil people, it's because any bit of information could open up the potential for a law suit, even if in good spir…

That is the usual stated justification, and may actually be the motivation where it's become accepted as conventional wsdfom, but it's implausible on its face as a real justified concern, because it's just as easy for a rejected subject to infer ill intent from a refusal to explain as from an innocuous explanation.

The real reasons for such policies send to be a combination of:

(1) Regardless of organizational policies, hiring managers will still sometimes use directly prohibited criteria, and some of them will clumsily reveal this (perhaps in ignorance of the prohibition) if they provide explanations. A clear blanket corporate no-explanation policy doesn't prevent the bad acts, but prevents the bad acts that slip through other corporate policies from being announced to victims, and

(2) Hiring criteria that aren't directly prohibited may be prohibited indirectly due to disparate impact. Providing honest explanations for negative decisions makes it possible for people who gain access to the explanations given to multiple candidates to discover disparate impacts, and take action against them, and

(3) People attempting to give honest explanations will sometimes explain things poorly in a way which indicates a prohibited (directly or indirectly) criteria was used, either positively (which might be evidence in other cases)) or negatively.

Re: GDPR: Don't Panic

#587

There's certainly no need to panic. The article doesn't address that apart from mindless hysteria there are some very real issues with GDPR. It doesn't have to of course because as the title suggests it's more about dispelling panic than about giving concrete advice. However, many real-life problems seemingly haven't even been considered by legislative bodies. In GDPR support forums questions like these have been rou…

>How will I be able to operate my small company website in the future in a legally compliant manner?

Maybe you shouldn't operate your company if you can't comply, then. The entire point of the GDPR is elevating privacy as a priority. If that means companies that can't or won't compy can't operate, so be it. People always claim to be pro-privacy, and that means putting privacy above commerce, in the same way that a restaurant that can't or won't meet safety and sanitation regulations shouldn't operate.

Re: GDPR: Don't Panic

#588
> This in no way should be read as you, the small business operator will face a fine of 20 million for each and every infraction that could be found.

Thank you, random stranger on the Internet! However, that is not the law. And even if you are right? As I posted yesterday, half of the employers in the USA has 1-4 employees and make $387,200 on average yearly. Even if they get fined to 1% of the maximum, they are completely wiped out. So no, it's not hysteria, it's plain business sense for them to slap an IP ban on it and move on.

Re: GDPR: Don't Panic

#589

Earlier quoted context omitted.

> It is irresponsible not to assume that if the law is written a certain way then at some point, the law can (and likely will) be enforced that way when it suits the government. With the caveat that "the law" in this case isn't just the GDPR, it's the entirety of EU case law. GDPR exists in a particular legal context.

I get the impression I am misunderstanding EU law (not necessarily a surprise) when folks say things like "Civil law vs. Common Law" or "legal context." If a law is on the books, it can be enforced in the EU, right? I understand there is precedent but precedent is not law, it's merely the common understanding of that law in that particular context. Precedent is overturned all the time (not to mention ignored when con…

That is a fine analysis but I'm not sure what your question is. All laws exist in a legal context and analyzing them while being ignorant of that context is futile. That's all I was saying. I think almost all the people armchair-analyzing the GDPR in a hyperbolic manner would be equally useless at analyzing their own laws, in their own countries, for what it's worth. (someone in another comment said something contrasting the EU with places where laws are "not open to interpretation." Dear lord...)

That doesn't mean Jacques' analysis is not worthwhile, by the way. He is not ignorant of the legal context. Judging by the reaction to the article, this is going to be one of those situations where you can lead a horse to water but you can't make him drink.

Re: GDPR: Don't Panic

#590
post #120

Earlier quoted context omitted.

It is highly unlikely that a lot of requests will "sink" your company. As per the GDPR, you have a month to respond to requests and you can extend this period by two more months by telling the user that you need more time to process their request. (See article 12 for reference)

If 10% of the members of my website request a GDPR, then my website will no longer exist. The processing time for that would be a decade.

As said below, this can be automated. If you can't or won't comply, then your website shouldn't exist.
Post reply on HN