Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

591–600 of 833 posts

Re: GDPR: Don't Panic

#591

Earlier quoted context omitted.

>we can trust EU regulators I want to stress that this is a major point of political polarization in Europe at the moment. Even if this claim is true, it warrants a clear and articulated defense.

Agreed, for some reason people tend to forget that Austria, Italy, and the UK among others have explicitly said the opposite of this

I mean some of those are bad examples, like the UK's government isn't great w.r.t. privacy (Investigatory Powers Act). Shocker that they might disagree with EU regulators.

But fair enough, nobody should be trusted blindly. This is why we have appeals and legal avenues to create checks and balances. So in the context of this discussion, it's pointless. We don't have to trust them. If a fine looks disproportional, there are legal remedies. Up to the ECHR which is generally quite careful in it's decisions.

If you don't trust the EU's legal system, that's a different problem. One that rings a bit hollow, and doesn't really further the GDPR discussion.

Re: GDPR: Don't Panic

#592
post #491
post #358

Earlier quoted context omitted.

> A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR Come on, this is just scaremongering. Newsflash: If you run a business, you are already responsible for adhering to hundreds of other laws in which the fines could reach millions. But you don't see people running around screaming that the world is ending, because they know that the laws will generally be applied f…

> you are already responsible for adhering to hundreds of other laws in which the fines could reach millions. Source please? > If you are going to crank the anxiety to 10 every time a situation like this occurs, you probably shouldn't be running a business or handling others' data in the first place. I'm not running one right now. It's not the situation that give me anxiety, it's just that it no longer seems interest…

Canadian here. You are making assumption about decisions you don't know about,- like "Do theses companies had too much anxiety for our regulation? None at all, they were some multi billions companies that did this. It was just not worth it."

That is a sweeping generalization and if you dilute and guess what the most probable reason for excluding Quebec was,- it's probably for the best. It was a shady contest to begin with.

The Canadian sweepstakes law and corresponding province laws are not that hard and costly to comply with as well. Look at the countless valid and non-scam contests present and available to our citizens. You, I and rest of us should be glad that rules like these exist since a there are people companies out there willing to part you with your hard earned money.

As an example, you just need to store my skill testing answer and if I get awarded a price, reset a flag that I need to fill out a new answer. In Quebec, you need to give monetary guarantees to make sure you pay out and give contest rules out to the bureau ahead of time. That is not a tall task. It's for the better if those shady contests did not want to participate

Re: GDPR: Don't Panic

#593
post #381

Earlier quoted context omitted.

Because those people tend to come from a country which doesn't have laws open to interpretation and thus mark people who drunkenly pee on a fence with the same sex offender tag than child molesters. If you're country functions in a way where laws can't be interpreted according to context it's hard to think of a different system.

Which is an indictment of the laws, but not necessarily the system.

But they are different systems. For example contracts in the EU tend to be way shorter, as long as you get the gist. Contracts in the US are painfully long, listing things out explicitly, etc.

This exactly what rules-based regulation (US) and principles-based (EU) regulation means, and why the GDPR is written the way it is.

Re: GDPR: Don't Panic

#594

Constantly trying to whitewash over the fact that GPDR is a huge pain in the ass and will involve a lot of work for a lot of companies is what I don't understand, but Mr. Mattheij has been doing it for months, so that's evidently very important to him for some reason. It's chewed up a few weeks of active development time putting in features for purging and exporting anything that looks like it might be personal infor…

One might argue that your company doing the "custodial" data work over the past few weeks and building in the mechanisms in order to handle that data in a more nuanced way is something that should have been done beforehand, and that the fact that you had to take time out to look at it means the law is doing exactly what its drafters wanted it to do.

Re: GDPR: Don't Panic

#595
post #189

Earlier quoted context omitted.

Run your small company website without gathering personal data? No-one can sue you now, that couldn't before. I'm baffled that so many people believe this. I could complain about you to my country's regulation body. Then they could decide to audit you, and for a first offense issue a warning. If you need the address data for marketing only, and you didn't get an explicit (opt-in) yes to receive marketing, then sorry.…

I liked the aisle, but have a lot of issues with it. This is one of my main ones: IP addresses and information security. Quoting you: > Storing an IP for a limited time for security reasons is fine. Have rules in place for how this data is used and when it is deleted. Don't keep it longer than nessescary. How long is necessary? What does limited mean? Does a regulator now get to determine what sort of algorithms I ca…

> How long is necessary?

As long as is needed for the stated purpose. If you're doing IP-based rate limiting with a 1 hour window, it probably doesn't need to still be in your systems >12 hours from now. If you're doing longer term IP reputation or something, keeping it around longer can probably be justified.

> What does limited mean?

The same. Long enough to serve its purpose, and no longer (without justifiable exception, such as being evidence of an actual crime, etc)

> Does a regulator now get to determine what sort of algorithms I can use

Not really, any more than they already do.

"Not guilty, Your Honour; you see, we do store people's HIV status against their real names on the public blockchain, but don't worry, it's ROT-13 encrypted! Twice!"

Also, remember that it's not really the IP that you care about (from a privacy perspective). An IP+timestamp is a very discerning selector, if you have any other data at all.

Nobody knows that '192.168.1.1' is actually me. And even if they did, does it really matter?

But maybe they know that only $IP hit /orders/confirm within 5 minutes of some other system recording that $ME placed an order with other details.

From a privacy standpoint, it's your ability to cross-correlate that IP and whatever else you know about it that could allow identifying and tracking/profiling the actual person using it.

Suppose your marketing dept asked you to scan the last few weeks of security logs to see if you'd had any hits from ranges belonging to $BIGCORP who you're in tense negotiations with? Is that Ok? Or would you refuse because the security logs are collected exclusively for certain purposes of which that isn't?

Re: GDPR: Don't Panic

#596

The GDPR gets so much hate because it hits so many businesses where it hurts: data. GDPR "simply" gives you guidelines on how you can handle data from people within the EU. And that that data cannot be handled so liberally as it has been before. Of course that's annoying from a business perspective, but from an individuals privacy perspective, it's fantastic.

It's not that it's annoying, it's that I literally cannot answer "are we GDPR compliant?". If you search for GDPR IP address, you get a ton of different opinions. Do I need to sanitize logs? How does that fit in with the requirements for security compliance we are also subject to? At the end of the day, I am the one person who has to answer that question/is responsible for being GDPR compliant. I've spent hours doing…

So everything should be written out explicitly, because you'd rather complete a checkbox-ticking exercise rather than thinking about it and do the correct, ethical thing in good faith?

Sounds like a win for the GDPR to me, we know rigid checkbox-ticking is ineffective.

Apart from that, NIST 800-53/800-171 are catalogs of "security controls and associated assessment procedures" for "Federal Information Systems and Organizations". GDPR is a data protection regulation in the context of the EU legal system. Apples to oranges.

Re: GDPR: Don't Panic

#597

Earlier quoted context omitted.

> It turns out that the vast majority of contractors and freelancers were operating in that fashion legitimately and continue to do so Which we know is definitely NOT the case for companies storing your data correctly.

Are you claiming that most companies are not storing data in compliance with current law today? There's a meme about how all businesses are trying to exploit personal data mercilessly at any cost, yet among the small businesses around here and the people I know who work there, none of us is in that line of work, nor I suspect would any of us want to be.

There is a bigger problem with GDPR compliance.

Say I use a DDoS prevention service (like cloudflare). They get my user data, and also have to be under scope of GDPR as well. And since IP isn't indicative of EU citizenship status, a company had better apply GDPR to everything rather than just a subset.

In the end, this law makes a "We respect the privacy of your data" subset of providers, and provides a great way for us users to identify bad actors (Google, FB, Amazon, etc).

Re: GDPR: Don't Panic

#599

Earlier quoted context omitted.

It's not that it's annoying, it's that I literally cannot answer "are we GDPR compliant?". If you search for GDPR IP address, you get a ton of different opinions. Do I need to sanitize logs? How does that fit in with the requirements for security compliance we are also subject to? At the end of the day, I am the one person who has to answer that question/is responsible for being GDPR compliant. I've spent hours doing…

So everything should be written out explicitly, because you'd rather complete a checkbox-ticking exercise rather than thinking about it and do the correct, ethical thing in good faith? Sounds like a win for the GDPR to me, we know rigid checkbox-ticking is ineffective. Apart from that, NIST 800-53/800-171 are catalogs of "security controls and associated assessment procedures" for "Federal Information Systems and Org…

If I'm going to be fined or penalized for not being compliant then yes, explicit would be nice. Checkboxes sound great.

Re: GDPR: Don't Panic

#600
post #537

How can I be non-compliant with GDPR? If I could care less about it, is it enough for me to do nothing? Should I expect that European users should find out themselves that they my website is not GDPR-compliant? Or I must actively ban EU IPs?

If you actively choose not to pursue compliance, you should make it clear in your own privacy policy that the site is not for use by EU/EEA citizens and also use IP geolocation to block their requests.

You should require users to positively certify that they are not EU/EEA citizens, and refuse service if they are. Blocking by IP is a good idea but not sufficient.
Post reply on HN