Live data from Hacker News

UK to depart from GDPR

lawgazette.co.uk

611–620 of 659 posts

Re: UK to depart from GDPR

#611
post #581
post #490

Earlier quoted context omitted.

Gdpr means you need to have a disagree button. Just click it for everything

(a) not everyone has a disagree button today (b) many people make the disagree button small, hard to see, or require clicking through multiple screens to get to GDPR really should have dictated "agree" and "disagree" be of equal visual weight and button styling and dictated disagreeing to be a 1-click action.

> GDPR really should have dictated "agree" and "disagree" be of equal visual weight and button styling and dictated disagreeing to be a 1-click action.

It does mandate something to that effect: the user should not have to spend more effort to disagree than to agree.

Re: UK to depart from GDPR

#612

Earlier quoted context omitted.

GDPR forced them to actual define policy, start deleting old data that was no longer relevant, strip private data from developer test sets. That is the theory. The reality is that many small businesses don't even know the GDPR exists. Others are not complying because they think they will get away with it, and they are probably right. The rules are so ambiguous in some important ways that even those who do intend to c…

In what important ways is the GDPR flawed?

One important way is ambiguity. For example, it relies on "legitimate interests" as a lawful basis for a lot of different types of processing, but there is no specific, actionable definition of that term. This is compounded by the right of the data subject to object to some processing, but again with only an ambiguous specification of when those rights take precedence over the legitimate interests of the data controller (other than a few specific cases, such as direct marketing).

As another example, there is a new subject right to erasure of their data, though again this isn't absolute. Several potential complications were discussed about this right. One is how to handle copies of that data in back-ups, archives or retired equipment. Another is how to deal with data held in deliberately tamper-proof formats, some of which will already have existed before this right to erasure was introduced by the GDPR.

Another important way is the compliance costs, and in particular the disproportionate costs to small businesses. For example, it cost mine many hours and thousands of pounds to understand the new requirements, take advice, and update our documentation to be compliant, yet the actual data processing we did was always very light and so wasn't affected much by the new rules either. In other words, it cost us a significant amount of time and money without really benefitting anyone.

Related to that is the enforcement mechanism and penalty regime. Regulators are all-powerful, and again, while they can impose some heavy fines on big businesses, those are meaningfully capped. In contrast, the rules allow them to impose penalties high enough to literally destroy any SME. The practical safeguards are the limited resources of regulators and the idea that those regulators are supposed to work collaboratively with data controllers and impose proportionate penalties for any compliance violations that can't be resolved, but this is awfully close to relying on personal judgement and good will, not what is actually written in law.

Then there is the reality that the GDPR doesn't actually do that much to protect against some of the biggest threats to personal privacy. For example, I would argue that two of the biggest risks in our modern "big data" world are excessive collection and processing of personal data supplied by third parties and excessive collection and processing of data by governments. The GDPR has done very little to curb either of those things. Every time I go out, I'm still potentially being listened to or photographed by countless other people's devices, which may then be uploading that data to big tech firms along with time and place information. Countless people have probably handed over my phone number or email address to big tech firms by allowing apps to scan their address book. We still see ever more intrusive monitoring of normal people's daily lives by governments, with tech like facial recognition cameras or mass surveillance of communications routinely infringing on personal privacy, and the authorities pushing for these things are entirely unrepentant and rely on the usual vague justifications about security and what a dangerous world we live in.

In short, the GDPR imposes significant burdens on data controllers without being clear about what their obligations or how to interpret key details in practice, introduces a penalty regime that hangs like a sword of Damocles over data controllers and represents an existential threat to smaller controllers, and yet at the same time hasn't actually been very effective at reducing the big risks to data subjects or increasing their control over how data about them is used and by whom.

None of these concerns is new. All were discussed extensively around the time the GDPR was introduced. But, perhaps because it was a law meant to improve individual privacy and that's a cause many of us support in principle, sometimes people get very defensive of it instead of looking at it critically and asking whether it actually achieves what it set out to do and whether any costs it introduces are proportionate to any benefits it offers.

Re: UK to depart from GDPR

#613
post #549
post #539

Earlier quoted context omitted.

Is that a sarcastic comment? Because GDPR allows for liquidating fines, even for Google. I believe it has a cap of 2% annual global turnover, per infraction, or something similar. Problem is, GDPR is not enforced. I haven't heard of small companies being investigated, let alone having any fines imposed, even when blatantly violating GDPR.

Just because you haven't heard of it doesn't mean it doesn't happen.. https://gdpr-fines.inplp.com/list/ https://www.enforcementtracker.com/

All those fines seem pretty reasonable, I don’t see any questionable or odd interpretation of the rules?

Re: UK to depart from GDPR

#614

Earlier quoted context omitted.

In what important ways is the GDPR flawed?

One important way is ambiguity. For example, it relies on "legitimate interests" as a lawful basis for a lot of different types of processing, but there is no specific, actionable definition of that term. This is compounded by the right of the data subject to object to some processing, but again with only an ambiguous specification of when those rights take precedence over the legitimate interests of the data control…

Most laws are fairly ambiguous. Jurisprudence and intent play a big role in the justice system, it works to protect people from wrongdoing and not as a strict logical set of rules.

Being filmed in public, having your data handed to third-parties, facial recognition and mass surveillance are precisely some of the issues the GDPR has addressed, and it has already had massive impact; especially on tech companies (I’ve seen it firsthand). You talk about burdens but maybe you’re just angry you wasted money on a consultant? I honestly haven’t seen the bad side of it.

Re: UK to depart from GDPR

#615
post #614

Earlier quoted context omitted.

One important way is ambiguity. For example, it relies on "legitimate interests" as a lawful basis for a lot of different types of processing, but there is no specific, actionable definition of that term. This is compounded by the right of the data subject to object to some processing, but again with only an ambiguous specification of when those rights take precedence over the legitimate interests of the data control…

Most laws are fairly ambiguous. Jurisprudence and intent play a big role in the justice system, it works to protect people from wrongdoing and not as a strict logical set of rules. Being filmed in public, having your data handed to third-parties, facial recognition and mass surveillance are precisely some of the issues the GDPR has addressed, and it has already had massive impact; especially on tech companies (I’ve s…

While many laws are somewhat ambiguous, usually the intent is reasonably clear, and there are courts to decide cases where there is a disagreement about interpretation. The GDPR doesn't have either that clarity of intent or that independent, impartial form of adjudication.

We didn't hire a consultant. Those guys were charging thousands per day, and no business our size has that kind of money to spend. We did take real legal advice from a real lawyer, but the main cost was our time understanding the new rules and updating things to be seen to be compliant. I am irritated that a lot of my own time, as a founder and at that time lead technical person for a business, was wasted on a bureaucratic exercise, and likewise for other key people. That hurt us, and once again, it benefitted no-one. Not our customers. Not our staff. Not our suppliers. Literally no-one was better off because, for example, we rewrote our documents to provide information in some new format that was specified by the GDPR.

Personal irritation aside, even if you just took the cost to us and scaled it by the number of businesses in the country to estimate the economic impact, that would mean billions in lost productivity as a result of the new rules. And that's clearly an underestimate, as the costs were running into millions for a lot of large organisations. A law that is going to cause that kind of economic hit should be justified by a greater benefit to society in some way, but I just don't see that "massive impact" you mentioned. There have been a few incremental changes here and there, but there hasn't been a big change in culture.

The attitude at bigger organisations is still often about how they can tick the required boxes while continuing to do what they want with the data. Just look at Facebook's resistance to even disclosing what personal data it has and how it's been using it, for example, despite data subjects having a clear right to that information under the GDPR.

Tracking is still going on everywhere, and if anything it's getting worse as the technological capabilities increase. Ironically, it's recent actions by Apple, not the GDPR, that have started to make some significant improvements in this area for users on their platform.

Small organisations are still often ignorant of their obligations under the GDPR and not compliant anyway. Governments are still encroaching further into individual privacy all the time. Individual privacy hasn't been improved at all in these kinds of situations.

This will be my last comment on this thread, because HN tends to downvote any comments critical of the GDPR, even if based on direct personal experience of implementing it, and that doesn't encourage open and constructive discussion. But I hope the above helps to explain why I have reached a different conclusion about these issues to you.

Re: UK to depart from GDPR

#616

Earlier quoted context omitted.

> have more historical evidence of supranations falling apart Debatable. But even if the EU was - or was not - a tightly integrated federated state, I'm far more concerned about the UK withdrawing itself from the world's largest free trade bloc. I see it heading towards either economic protectionism (bad in the long-term) or getting into a race-to-the-bottom (potentially even worse).

> either economic protectionism (bad in the long-term) or getting into a race-to-the-bottom (potentially even worse) That's a strange thing to say. Globalisation is usually criticized as a race to the bottom. The opposite of that is protectionism, which you say is bad. So which one are you in favour of?

Globalisation allows local economies to specialise and reduce economic waste (e.g. what if every country had its own car factories?) I appreciate that globalisation will lead to localised races-to-the-bottom in the near-term, but in the long-term everyone benefits. Protectionism (for the sake of securing jobs) feels good in the short-term but very few mainstream economists will advocate for it absent other concerns (e.g. safety standards, cultural imports, national security, and human-rights concerns).

Take the UK for example: at the time of its accession to the EU it had a sizeable manufacturing and mining economy. Globalisation directly led to those factories and mines closing, but being in the EU meant the UK could specialise in emerging sectors and immediately export to the rest of the EU for free (e.g. service-sector, information economy, banking, finance, media, etc).

Globalisation and economic-interdependence is also the main driver for world-peace. I’d rather be unemployed because someone in France does my job but cheaper than be fighting in a war against France for some sense of “national pride”.

Globalisation needs a friendlier face, yes. And we need better ways of managing the local negative effects, like better unemployment income for plant closures - but I don’t believe the sentimental negatives in any way outweigh the long-term benefits.

Re: UK to depart from GDPR

#617

Earlier quoted context omitted.

"everything would be perfect if only EU stopped interfering with our perfect country" will disappear from political speech. That doesn't seem to be disappearing. My guess is we will be hearing a lot more about the EU for the foreseeable future.

One or two election cycles, but afterwards it will be too boring to hear the same excuses. Soon after dissolution of Czechoslovakia, people in Slovakia blamed Czechs for all kinds of things. (We had an agreement that neither side will use the old federal flag; they kept it. We had an agreement that the national treasure will be split proportionally; they decided to keep it all. Plus a few more things. I am sure the o…

Go and ask the people of Switzerland about that because my understanding is their relationship with the EU is in constant negotiation.

>Farage will be just some uncool old grandpa

Fortunately that has already happened.

Re: UK to depart from GDPR

#618

Earlier quoted context omitted.

There's fierce a competition amongst many countries of the world to see who can shove their tongue furthest up the USA's arse. The UK may be out in the lead [through sheer long-term dedication to the cause, if nothing else]. But the equally supine devotion of countries like Australia, NZ, Germany, Ireland, Poland, Iceland [and several others] shouldn't be under-estimated.

I upvoted Normille’s comment to offset the downvotes. It may have been crudely put but it’s not wrong – at least in the case of Ireland, the country I know best. For as long as I can remember, the Irish government has been quite deferential towards the US, e.g., allowing the use of Irish airports (mostly Shannon, a civilian airport – but also Casement Aeorodome, the headquarter of the Irish Aer Corps) by US military…

Irish myself. So I upvoted you back for expanding on my [perhaps puzzling to some] inclusion of Ireland in the list of US sphincter hygienists.

Ireland is officially a neutral country but, as you correctly point out, has a long history of allowing the US to use Shannon as a de facto US Airbase. And, as you also correctly point out, has almost built its entire economy in recent years on providing tax incentives and other bribes for US mega-corporations to set up [nominal] HQ there. The phrases "House of Cards" and "They don't love you back" immediately spring to mind.

Re: UK to depart from GDPR

#619

Earlier quoted context omitted.

An email address is PII. Given that many preexisting systems used email addresses as usernames to identify users, let’s say a small business in 2015 hired a company to create a web app which let a user create an account using their email address and it put the email address into a log file with that user’s activity. The contracted developer finished the site, which cost 25000 EUR, much more than the business could af…

So peoples PII should be just sitting there unregulated because companies can't afford to clean up their privacy messes?

You are asking a question as if this was some sort of moral issue, and that's pretty much guaranteed to lead to terrible decisions -- ultimately immoral decisions -- so my advice is to not approach technical problems through a moralistic lense, but through a technical lense.

The situation we have now is that massive amounts of code and business processes that were created without the assumption that things like email addresses were protected information that users have a right to purge whenever they want. It doesn't particularly matter if you think this is right or wrong, what matters is that this is how the world is. So then, what to do about it?

A rational approach is to try to look at a cost-benefit analysis of various solutions -- how much would it take to refactor the code and update the business processes? More importantly, how much would it take to put into operation controls that effectively ensure that all the data was deleted? Finally, how much would it cost to get rid of all that data -- remember companies can have tape backups, recovery centers, and data was sprayed everywhere for decades.

So you get some number, say a hundred billion. Is it still worth the expense? Could there be some other solution?

For example, force companies to delete old data after X years, where X is say 10 after the business relationship has been ended. Or some other approach. That approach might cost only 20 billion. Or force companies to do this for new code and business processes but leave the legacy ones in place for X years. That might be only 10 billion.

As another example, look at C code. It's unsafe. We are aware of the problems with C code now and have discovered safer languages. But the cost of rewriting the existing pool of C code is huge. It doesn't help to wring your hands and approach this from a moral argument -- so security doesn't matter, we declare indignantly? Instead, look for practical ways of transitioning to safer languages over time, and other ways to isolate and mitigate the damage of unsafe code.

But at all costs, understand the limitations involved, and craft remedies that give you the most bang for the buck, because resources are limited and a dollar spent on this is a dollar not spent on some other cause, which might be more worthwhile than being able to delete any email address on command from a customer letter.

Re: UK to depart from GDPR

#620

Earlier quoted context omitted.

Are you in the EU? I'm a developer in the EU and that is patently not true. Developers have to have mechanisms in place to delete gdpr data when required and not store data that's not required for you goals. In my experience gdpr puts a real and meaningful curb on the strong impetus to gather everything and sell it.

> Developers have to have mechanisms in place to delete gdpr data when required and not store data that's not required for you goals Purely anecdote, but zero companies I know in Germany, Italy or France are doing this. (The ones in Switzerland are.) There is a cosmetic fix that produces an email so there is something to show a regulator if they come knocking. The logic being investing anything more than that is a cr…

My previous client is a reasonably large Swedish company with a big German presence and they took GDPR (and data protection in general) EXTREMELY seriously. I know because, outside of the training, I sat in on a few audit meetings.
Post reply on HN