Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

61–70 of 833 posts

Re: GDPR: Don't Panic

#61

Earlier quoted context omitted.

On what experiences with EU bureaucracy do you base your statement?

On what experiences with EU bureaucracy do you base your question?

I don't know about them, but I agree with questioning your original comment, based on 17 years of dealing with data protection issues in the UK and other EU countries.

Re: GDPR: Don't Panic

#62
post #48

This doesn't consider some factors that dictate how strong any company will experience their firehose of GDPR requests to be: - how incentivised people are to make GDPR subject access requests of the company (how angry, confused, hostile curious they are) - how easy it is for them to make requests (entirely manual vs. online service) - wildcard factors (internet flash mobs bent on vengeance against a corporate) There…

This sounds like the arguments that organisations make against freedom of information laws. There is that risk, but what is the alternative? There doesn't seem to be a middle ground to me - either people can make subject access requests or they can't.

FOI laws apply to governments, not corporations.

And yes, civil servants did use those arguments to try and stop FOI. They lost because ultimately they pay themselves out of tax revenues, and when you force people to buy something the bar for denying them information about how that money is used is a lot higher.

This doesn't apply in the case of companies and especially not job candidates.

Re: GDPR: Don't Panic

#63
post #48

This doesn't consider some factors that dictate how strong any company will experience their firehose of GDPR requests to be: - how incentivised people are to make GDPR subject access requests of the company (how angry, confused, hostile curious they are) - how easy it is for them to make requests (entirely manual vs. online service) - wildcard factors (internet flash mobs bent on vengeance against a corporate) There…

If you don't have a talent pool, one should remove all candidate data after rejection. It's probably better to outsource talent pools.

Re: GDPR: Don't Panic

#64
post #48

This doesn't consider some factors that dictate how strong any company will experience their firehose of GDPR requests to be: - how incentivised people are to make GDPR subject access requests of the company (how angry, confused, hostile curious they are) - how easy it is for them to make requests (entirely manual vs. online service) - wildcard factors (internet flash mobs bent on vengeance against a corporate) There…

This sounds like the arguments that organisations make against freedom of information laws. There is that risk, but what is the alternative? There doesn't seem to be a middle ground to me - either people can make subject access requests or they can't.

Not an alternative - but the only obvious defence is to do the right thing, and delete data as soon as you have completed processing. e.g. delete those interview notes the second you have declined the candidate.

Re: GDPR: Don't Panic

#65
post #37

The problem of multiple ambiguities in GDPR hasn't really been addressed here. Also, must be nice to live in a country where the regulator is as benevolent and reasonable as is described in this article. I think it's ok for foreigners to be skeptical of this promise, as the article implies that this reasonableness is not encoded in law.

Law is by its nature open to interpretation and based on precedent. Otherwise there wouldn't be courts of appeal and supreme courts. What's so special about GDPR that makes you think it will be abused more than other laws?

Re: GDPR: Don't Panic

#66

Exactly. People try to explain to me how it is impossible to comply and usually it turns out that it would be easy. I think the problem most of time that people misunderstanding the requirements or not reading GDPR (not even TLDR versions).

There is no "TLDR" of the GDPR. It has to all be read, understood and complied with. This is basic legal compliance, and is not at all easy for a small business.

Yes, and it is not that hard a read. The only problems people seem to be having are in trying to finesse the rules to avoid looking after data with due diligence. If you really want to look after data, then you just need to do that, and you will be compliant.

Re: GDPR: Don't Panic

#68

I'm not sure about the point regarding the DPD. EU Directives themselves don't have teeth, but they're supposed to be transposed into national laws - e.g. the DPA in the UK - and would be enforced nationally. A regulation comes into law across the EU, but is still often transposed, and the enforcement mechanism (to begin with) is still basically the same. He's right that the DPD was not well-adhered to, though.

[deleted]

Re: GDPR: Don't Panic

#69

Exactly. People try to explain to me how it is impossible to comply and usually it turns out that it would be easy. I think the problem most of time that people misunderstanding the requirements or not reading GDPR (not even TLDR versions).

There is no "TLDR" of the GDPR. It has to all be read, understood and complied with. This is basic legal compliance, and is not at all easy for a small business.

And if you are a small/medium business, don't comply and somehow are reported, you will receive an email from the regalutory instance of the country the person who reported you come from. They will tell you what is wrong and point you to some articles who can give you advices on how to comply. If you have difficulty to do so, you can contact them and ask specific advices, they will respond (probably a bit late) and as long as you comply with the RGPD within a month after that, you're good.

Audit can take some time and have a real impact on your business though, so i'm not saying everything is perfect. But to me, audit is the only thing you have to be really afraid of, not fines.

Re: GDPR: Don't Panic

#70
post #45

Earlier quoted context omitted.

Am in EU, am involved in some compliance stuff and have talked to plenty others at other companies, and it really does seem to be a nothing-to-see-here for all companies except the sleezy ones.

Is there even a single thing forbidden under GDPR that wasn't already forbidden before in at least half a dozen member states? In that case, it makes everything easier except for ignoring requirements.

I'm not certain about the other memberstates but to my knowledge the privacy law hasn't changed that much. There is a good increase in the amount of generating an audit log of any privacy sensitive stuff you do and of course the various "Right to be *" variants but those are largely non-issues.

German courts already considered a EULA or "check box to consent and get thing" a non-binding consent (to some extend).

Largely, if you are running afoul the GDPR in germany there is basically two options A) you rely on adsense a lot and B) you ran afoul the previous laws already.

So, overall, I would say that yeah, most of the stuff forbidden by the GDPR was already forbidden. The GDPR grants you new rights and requires corporations to ensure compliance however, that's new.

Plus the teeth in form of pretty hefty fine limits. Which is good IMO.

Post reply on HN