Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

601–610 of 833 posts

Re: GDPR: Don't Panic

#601

Earlier quoted context omitted.

> EXACTLY! There seems to be an almost cultish devotion to the benevolent institution that it can do no wrong, neither now nor henceforth. You have to trust someone. Either the vast expanse of companies clearly mishandling your data, or the "benevolent" body which so far at least has a fairly good track record. It's not perfect. It's dangerous to give them too much power because you don't know how they will change in…

A fairly good track record in which its own member states are constantly threatening to leave and one has already successfully left. As an American lokoing in from across an ocean, it does not look like a stable region that I would put trust in

As a fellow American, that sounds like you need to reconsider your news sources. Brexit was driven by propaganda, not some principled opposition to intractable problems. The “EUrocrats gone wild” stories are popular in certain circles but there’s an entire cottage industry debunking them:

https://en.wikipedia.org/wiki/Euromyth

Re: GDPR: Don't Panic

#602
post #513

Earlier quoted context omitted.

Yes and there's nothing saying I won't be arrested and thrown into a cell for the rest of my life if I say something incorrect by mistake when entering the US. There's nothing that says IRS won't prosecute you if someone buys you a soda and you don't declare it as income. Or that you won't be prosecuted by someone in the US if your blog has a copyrighted image and you don't receive a DMCA request that was sent to you…

> I won't be arrested and thrown into a cell for the rest of my life if I say something incorrect by mistake when entering the US For the rest of your life? Source please? You can be put temporarily into a cell for plenty of stuff but that's temporary. A fine is pretty permanent and when it can be millions, well that's probably the end of your business too. > There's nothing that says IRS won't prosecute you if someo…

The IRS is probably the best US example of "proportionate punishments" and why people should not be overly afraid of GDPR.

The tax laws are vastly more complex than GDPR. The maximum penalties for tax fraud seem to be $250,000 + cost of prosecution + 5 years in jail.

If you make a small mistake on your taxes, and the IRS notices, you will probably receive a warning and have to repay it with interest. If you make a negligent mistake, you may be in addition be fined a small percentage, like 10-20%, of the amount you failed to declare. You have to conduct very large scale and intentional tax evasion for the maximum penalties to apply.

The IRS could argue for and try to apply the maximum penalties for a lemonade stand, but they don't. And people go on with their lives, put in their best effort to comply, and can be confident that they will be treated fairly.

Re: GDPR: Don't Panic

#603

Earlier quoted context omitted.

Are you claiming that most companies are not storing data in compliance with current law today? There's a meme about how all businesses are trying to exploit personal data mercilessly at any cost, yet among the small businesses around here and the people I know who work there, none of us is in that line of work, nor I suspect would any of us want to be.

There is a bigger problem with GDPR compliance. Say I use a DDoS prevention service (like cloudflare). They get my user data, and also have to be under scope of GDPR as well. And since IP isn't indicative of EU citizenship status, a company had better apply GDPR to everything rather than just a subset. In the end, this law makes a "We respect the privacy of your data" subset of providers, and provides a great way for…

a company had better apply GDPR to everything rather than just a subset

And that's what Cloudflare chose to do. We are treating all customers the same regardless of location.

"Of the companies I spoke with for this story, both Cloudflare and Mozilla will be GDPR compliant no matter where their customers are located." https://www.fastcodesign.com/90171699/what-is-gdpr-and-why-s...

Re: GDPR: Don't Panic

#604

Earlier quoted context omitted.

And rules-based regulation means you commit 3 felonies per day https://www.wsj.com/articles/SB10001424052748704471504574438...

Going on a bit of a tangent here, I am becoming concerned with how we discuss these things. You're completely either for or against it. And if you're against one way you are automatically for the other. If you think one thing is bad, obviously you need to be corrected that other thing is bad too. And then you'll get extreme examples showing it. Call it whataboutism, appeal to emotion, whatever. Every time these GDPR…

I think this is a situation where it's easy to see the mote in someone else's eye. I tried to provide a summary using the standard terms for both approaches (in practice, making it clear I preferred a principles-based approach); you jumped up to rebut (in practice, by trying to find the most derogatory synonym for "principles-based regulation" and accusing opponents of "frothing at the mouth"). And then both of us are astonished by the level of partisanship in this argument ;)

It's true, I do think that a more principles-based approach is usually preferable. (And I will happily marshal anecdata to that end!)

But it's naive to think that any approach comes without a cost. Even the PayPal example I mentioned above could be coloured the other way: A company makes a major investment in a foreign market, only to find the rules changed underneath them by a capricious government agency! (Someone brought up IR35 down-thread, and that's an excellent example too.) Is that an acceptable cost for the outcome? I'd look at the overall state of (eg) consumer financial protections in the US vs the UK and say "yes"; but I'm open to evidence-based disagreement.

Re: GDPR: Don't Panic

#605

Earlier quoted context omitted.

There is nothing - and I do mean nothing - written into the GDPR that requires any warnings of any kind, or places any limits on fines, except for $10/$20 million or 4% of revenue, whichever is greater. Period. A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR. The idea that "yes it says that but we can trust EU regulators to not assess large fines against foreign…

I think you and everyone making similar points in this thread are getting tripped up by the difference between rules-based regulation and principles-based regulation. This is unsurprising, given that the US is so heavily rules-based, but the EU (certainly the UK) has a long history of principles-based regulation. In rules-based regulation, all the rules are spelled out in advance, and the regulator is basically an au…

> In rules-based regulation, all the rules are spelled out in advance, and the regulator is basically an automaton once the rules are set.

Given that description, after a couple decades working in some and dealing daily with the acts of other agencies who which issue and apply regulations on the US, let me assure you that the regulatory system in the US is nothing at all like “rule-based” as you have described it.

Re: GDPR: Don't Panic

#606

I think much of this probably comes down to cultural and ideological differences between the US and the EU. It certainly seems that almost all of the rabidly pro-GDPR crowd is from the EU. Interesting: I have a number of anti-GDPR comments here and on last night’s GDPR thread that got upvotes last night US-time, heavily downvoted throughout the night, and are now going back up :)

Yes, because being against a law that is both reasonable and the right thing to do doesn't make any sense when you're a real live human being. The hysteria about businesses imploding under legislation is classic internet outrage at a phenomenon not very well understood. If you actually took the time to read the source material, you could very see that it's reasonable and made to protect you. At the same time, you would see that there will not be any world-ending fines handed out for literally no reason (on a slight tangent I don't understand why it is so impossible to grasp that this isn't something that happens in the EU).

Re: GDPR: Don't Panic

#607

Earlier quoted context omitted.

Example: How do you ask user for a permission to log access logs (which contain IP address) in the server, so that you can detect spam, ddos and other attacks? How do you store that consent information and what do you do if user doesn't consent? What do you do if user connecting from given IP address wants you to send him data you have collected about him. If people share IP addresses how do you know which log data i…

Some entity runs a webserver. This entity has a legitimate business purpose in retaining access logs for e.g. 3 months for e.g. spam and security reasons. This entity just has to document that. This entity can allow a 3rd party service to access these logs so that 3rd party can do whatever needs to be done if it is within the reasons the entity gave for having the data. What neither can do is go use that data for any…

Who defines what is a legitimate business purpose? Let's say I comply with all that, but someone makes a complaint and particularly bitter civil servant judges that the collection is not legitimate, because he doesn't like the content of the website?

Re: GDPR: Don't Panic

#608

I can tell you that GDPR is going to cause issues with block based backups. Many hosting providers don't separate customers on different block devices. When you back up a block device you have snapshots that have many different organizations data on them. Part of making good backups is knowing that the backup can't change. The only solution now is to add paths to go back and modify those backups to remove customer da…

The conventional solution to that problem I’ve heard for the last couple decades is to use encryption so the backup doesn’t need to be altered ahead of your normal rotation schedule as long as you can probably drop a customer’s key on demand.

Re: GDPR: Don't Panic

#609

Earlier quoted context omitted.

A lot of companies won't hire you if you have a criminal record of any kind. Some won't even hire you if you have any record of arrest, regardless of conviction. Which fraternity?

If the court seals the record its nearly impossible for anyone but government agencies to discover

> If the court seals the record its nearly impossible for anyone but government agencies to discover

No, it is not, because background check and other third-party intelligence firms aren't purely reactive now, they have and use tools to proactively vacuum up public records and maintain their own DBs. After-the-fact sealing of arrest records or expunging of convictions has no effect on data that is already in third-party hands.

Re: GDPR: Don't Panic

#610

Earlier quoted context omitted.

I read that GDPR applies to EU residents. That means someone who is EU resident non necessarily could be browsing from the EU. For example when on holidays.

Yes, but you cannot check whether a person is a resident unless you explicitly ask them. There are no "public" API. It's much easier and safer to just assume someone who's in Europe is a resident, rather than figuring out if they really are. GDPR only applies to EU residents, yes, but not if they're on ex. holiday outside of EU. Say, a EU citizen is on holiday in The U.S. In such case the EU citizen is not protected…

But this is only your assumption and not a fact. Person on holiday is still EU resident and enjoys protection of GDPR. Do you have a source that says that GDPR doesn't apply to IP outside of EU?
Post reply on HN